Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
uber-dot-arcanist
Advanced tools
This product encapsulates any arcanist plugins we depend on at Uber that are not included with arcanist itself. With this repo, you can avoid copypasta plugin folders in the .arcanist folder at the root of your project that are likely to be out of date.
Currently, this module contains three arcanist plugins:
To use this module, follow these steps from the root of your project:
# first make sure you have the most recent version of arcanist
arc upgrade
# install uber-dot-arcanist as a dev-dependency
npm install --save-dev uber-dot-arcanist
# if you currently have a .arcanist/ folder in your project, check it to make
# sure that is doesn't include any plugins that uber-dot-arcanist doesn't
# include.
# Legacy Uber projects may have tap, jenkinsphoo and jshintlinter. This module
# contains only the tap plugin as usage of the other two are deprecated at Uber.
ls -al .arcanist
# if there are no folders or directories in .arcanist besides jenkinsphoo, tap
# or jshintlinter, you can delete .arcanist. If there are any other modules,
# follow the instructions in the section 'How to handle other plugins in
# .arcanist'
git rm -rf .arcanist
After removing the .arcanist folder, you need to configure arcanist to load the
plugins from the node_modules/uber-dot-arcanist/.arcanist/
folder.
Open your .arcconfig
file and look for the load
property. It is likely to be
an array like so:
{
"load": [".arcanist/tap", "arcanist/uber-standard"]
}
If you see jshintlinter
or jenkinsphoo
in the array, you can delete those
elements. For tap
, you just need to prepend the path to the .arcanist
folder in this module. Assuming your load
value was the one right above, your
new values would be:
{
"load": [
"node_modules/uber-dot-arcanist/.arcanist/tap",
"node_modules/uber-dot-arcanist/.arcanist/uber-standard"
]
}
To add support for uber-standard when submitting differentials to Phabricator
with arc diff
, you can add the following to your .arclint
file.
{
"linters": {
"uber-standard": {
"type": "uber-standard",
"include": "(\\.js$)"
}
}
}
Once you've made these changes just stage your changes and commit:
git add package.json
git add .arclint
git add .arcconfig
git commit -m "Loading arcanist plugins from uber-dot-arcanist npm module"
If you encounter a plugin in your .arcanist folder that is not either tap
or
uber-standard
, you should first check the [phacility/arcanist][arcrepo]
to see if the plugin you are using is already part of the standard arcanist
install. If it is not, git clone this repo and add the plugin to this repo to
make it available to other engineers at Uber. Don't forget to add the repo to
the section titled "Included Arcanist Plugins" at the top of this README.
This module is just a wrapper around arcanist plugins. It is not callable as a library and contains no binary file. The tests just check that the expected plugins are included and that this module throws if called programmatically.
The MIT License (MIT)
Copyright (c) 2014 Uber Technologies, Inc.
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
FAQs
Uber's .arcanist folder as an npm module
The npm package uber-dot-arcanist receives a total of 4 weekly downloads. As such, uber-dot-arcanist popularity was classified as not popular.
We found that uber-dot-arcanist demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.