Huge News!Announcing our $40M Series B led by Abstract Ventures.Learn More
Socket
Sign inDemoInstall
Socket

sweetalert2-neutral

Package Overview
Dependencies
Maintainers
1
Versions
13
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

sweetalert2-neutral

A beautiful, responsive, customizable and accessible (WAI-ARIA) replacement for JavaScript's popup boxes, supported fork of sweetalert. Neutral version without 'protest-ware' features / spyware.

  • 11.14.1-neutral-fix6
  • latest
  • Source
  • npm
  • Socket score

Version published
Weekly downloads
2.6K
increased by279.59%
Maintainers
1
Weekly downloads
 
Created
Source

Sweetalert 2 NEUTRAL

If you use this library and find it useful, please share the fork existence upstream by opening an issue so other users impacted can migrate. Together we can fight Limonte's censorship!

This drop-in Swal2 replacement removes recent ongoing protestware "features" forcing Limonte's political views upon end-users, breaking automated tests and causing other harm along the way.

Original library is now "prohibited" to use in certain countries. This is however stated only in the readme, not in the license you obtain the source with and therefore probably isn't legally binding. For users with navigator.location matching ru, su or рф the original library now aggressively replaces the entire page content with Limonte's political messages.

There is now a 10% chance of displaying an unwanted banner & video on your site for visitors based on navigator.language if you are using upstream Swal2.

See: https://security.snyk.io/vuln/SNYK-JS-SWEETALERT2-2774674, https://github.com/sweetalert2/sweetalert2/pull/2462
Harm done by the original library: https://github.com/sweetalert2/sweetalert2/issues/2568, https://github.com/sweetalert2/sweetalert2/issues/2561, https://github.com/sweetalert2/sweetalert2/issues/2560, https://github.com/sweetalert2/sweetalert2/issues/2552

Install:

npm i sweetalert2-neutral

If using imports, replace:

- import Swal from 'sweetalert2';
+ import Swal from 'sweetalert2-neutral';

or use pre-built binaries.

FAQ

I am a Russian citizen, should I merge to Swal2-NEUTRAL?

Most certainly. Currently you could (in theory) end up in prison up for 20 years. See the law.
Limonte acknowledged this with sarcasm about npm ecosystem security.

I am a non-Russian citizen, should I merge to Swal2-NEUTRAL?

Most certainly. By merging you will mitigate the 10% chance of unwanted HTML being injected to your site. your entire page content being overwriten. See this issue or this one for the confusion this can create.

I want to have anti-war messages displayed on my site, should I merge to Swal2-NEUTRAL?

Most certainly. By merging you can decide which anti-war messages you want to display, instead of relying on volatile & abruptly changing implementation by Limonte.

Are there any other changes apart from removing "anti-war" messages?

No.

Are there any other benefits apart from unwanted banners not showing up on my site?

Yes, the library is ~5% smaller, thus less traffic is used and your site loads faster.

How do I migrate to Swal2-NEUTRAL?

  • When Swal2 is installed via npm: npm uninstall sweetalert2 npm i sweetalert2-neutral
  • When serving Swal2 via local files: replace Swal2 JS & CSS pre-built files

Aftermath

The original fork annoucement accumulated over 20 positive reactions, originally even Limonte reacted with "thumbs up". A few days later he changed his mind and resorted to censorship, deleting the annoucement:

image

Here used to be a note about how to sponsor the original Swal2 library, but due to censorship used by Limonte, this information is now removed.

Keywords

FAQs

Package last updated on 10 Oct 2024

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc