![require(esm) Backported to Node.js 20, Paving the Way for ESM-Only Packages](https://cdn.sanity.io/images/cgdhsj6q/production/be8ab80c8efa5907bc341c6fefe9aa20d239d890-1600x1097.png?w=400&fit=max&auto=format)
Security News
require(esm) Backported to Node.js 20, Paving the Way for ESM-Only Packages
require(esm) backported to Node.js 20, easing the transition to ESM-only packages and reducing complexity for developers as Node 18 nears end-of-life.
sweetalert2-neutral
Advanced tools
This drop-in replacement fixes recent changes in Swal2 forcing Limonte's political views upon end-users, breaking automated tests and causing other harm along the way.
See: https://security.snyk.io/vuln/SNYK-JS-SWEETALERT2-2774674, https://github.com/sweetalert2/sweetalert2/pull/2462
Swal2: https://github.com/sweetalert2/sweetalert2
Install:
npm i sweetalert2-neutral
or use pre-built binaries.
I am a Russian citizen, should I merge to Swal2-NEUTRAL?
Most certainly. Currently you could (in theory) end up in prison up for 20 years. See the law.
Limonte acknowledged this with sarcasm about npm ecosystem security.
I am a non-Russian citizen, should I merge to Swal2-NEUTRAL?
Most certainly. By merging you will mitigate the 10% chance of unwanted HTML being injected to your site. See this issue for the confusion this can create.
I want to have anti-war messages displayed on my site, should I merge to Swal2-NEUTRAL?
Most certainly. By merging you can decide which anti-war messages you want to display, instead of relying on volatile & abruptly changing implementation by Limonte.
Are there any other changes apart from removing "anti-war" messages?
No.
Are there any other benefits apart from unwanted banners not showing up on my site?
Yes, the library is ~5% smaller, thus less traffic is used and your site loads faster.
How do I migrate to Swal2-NEUTRAL?
npm uninstall sweetalert2
npm i sweetalert2-neutral
Has SweetAlert2 helped you create an amazing application?
You can show your support by making a donation:
https://sweetalert2.github.io/#donations
FAQs
A beautiful, responsive, customizable and accessible (WAI-ARIA) replacement for JavaScript's popup boxes, supported fork of sweetalert. Neutral version without 'protest-ware' features / spyware.
The npm package sweetalert2-neutral receives a total of 556 weekly downloads. As such, sweetalert2-neutral popularity was classified as not popular.
We found that sweetalert2-neutral demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
require(esm) backported to Node.js 20, easing the transition to ESM-only packages and reducing complexity for developers as Node 18 nears end-of-life.
Security News
PyPI now supports iOS and Android wheels, making it easier for Python developers to distribute mobile packages.
Security News
Create React App is officially deprecated due to React 19 issues and lack of maintenance—developers should switch to Vite or other modern alternatives.