
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
vue-preflight
Advanced tools
Vue.js plugin for route preflight actions.
Install
import VuePreflight from 'vue-preflight';
...
const vueProgressbarConfig = {
color: '#e53935', // Material design red 600
failedColor: '#7CB342', // Material design lightGreen 600
thickness: '5px',
autoFinish: false
}
Vue.use(VuePreflight, vueProgressbarConfig);
Mount progress bar in route component
<template>
<div id="app">
...
<vue-progress-bar></vue-progress-bar>
</div>
</template>
import store from '{path-to-vuex-store}';
import { preflight, withProgress } from 'vue-preflight';
const withPreflight = preflight(store);
// ...
const router = new Router({
routes: [withPreflight({ // Wraps route definition subtree in which you want
path: '/', // $_preflight to be enabled
children: [...]
}]
};
withProgress(router); // Sets progress bar controls on global navigation hooks
$_preflight
in component:<script>
export default {
/**
* @function $_preflight
* @param {Object} options
* @param {Object} options.$store Vuex store
* @param {Object} options.route Target route
* @returns {Promise | Object} Object or promise of an object to be
* assigned to component instance upon creation
*/
$_preflight() {
return doAsyncStuff().then(data => data);
}
</script>
FAQs
Vue.js plugin for route preflight actions
We found that vue-preflight demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.