New Case Study:See how Anthropic automated 95% of dependency reviews with Socket.Learn More
Socket
Sign inDemoInstall
Socket

sweetalert2-neutral

Package Overview
Dependencies
Maintainers
1
Versions
16
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

sweetalert2-neutral

Fork of Swal2 sans anti-war messages

  • 11.4.24-neutral
  • Source
  • npm
  • Socket score

Version published
Weekly downloads
649
decreased by-14.72%
Maintainers
1
Weekly downloads
 
Created
Source

Sweetalert 2 NEUTRAL

This drop-in replacement fixes recent changes in Swal2 forcing Limonte's political views upon end-users, breaking automated tests and causing other harm along the way.

There is now a 10% chance of displaying an unwanted banner & video on your site for visitors based on navigator.language if you are using upstream Swal2.

See: https://security.snyk.io/vuln/SNYK-JS-SWEETALERT2-2774674, https://github.com/sweetalert2/sweetalert2/pull/2462
Swal2: https://github.com/sweetalert2/sweetalert2

Install:

npm i sweetalert2-neutral

or use pre-built binaries.

FAQ

I am a Russian citizen, should I merge to Swal2-NEUTRAL?

Most certainly. Currently you could (in theory) end up in prison up for 20 years. See the law.
Limonte acknowledged this with sarcasm about npm ecosystem security.

I am a non-Russian citizen, should I merge to Swal2-NEUTRAL?

Most certainly. By merging you will mitigate the 10% chance of unwanted HTML being injected to your site. See this issue for the confusion this can create.

I want to have anti-war messages displayed on my site, should I merge to Swal2-NEUTRAL?

Most certainly. By merging you can decide which anti-war messages you want to display, instead of relying on volatile & abruptly changing implementation by Limonte.

Are there any other changes apart from removing "anti-war" messages?

No.

Are there any other benefits apart from unwanted banners not showing up on my site?

Yes, the library is ~5% smaller, thus less traffic is used and your site loads faster.

How do I migrate to Swal2-NEUTRAL?

  • When Swal2 is installed via npm: npm uninstall sweetalert2 npm i sweetalert2-neutral
  • When serving Swal2 via local files: replace Swal2 JS & CSS pre-built files

Has SweetAlert2 helped you create an amazing application? You can show your support by making a donation:
https://sweetalert2.github.io/#donations

Keywords

FAQs

Package last updated on 23 Jul 2022

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc