lspcontainers.nvim
ua-parser-js
Our great sponsors
lspcontainers.nvim | ua-parser-js | |
---|---|---|
8 | 29 | |
294 | 8,588 | |
2.0% | - | |
4.8 | 8.4 | |
4 months ago | about 1 month ago | |
Lua | JavaScript | |
Apache License 2.0 | GNU Affero General Public License v3.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
lspcontainers.nvim
-
Are the LSPs secure?
Here is the plugin: https://github.com/lspcontainers/lspcontainers.nvim
-
Looking for devcontainer solution in neovim
lspcontainers/lspcontainers.vim
-
I have just published nvim-dev-container plugin
It's not the same, but you might be interested in looking at https://github.com/lspcontainers/lspcontainers.nvim, which also deals with running LSPs in containers.
-
Good resource for setting up neovim for a 20++ year Vim user?
The third alternative is lspcontainers. Runs the language server process in a docker/podman container, which I think is fantastic.
-
Has anyone had success using lsp-ws-proxy?
You may want to check https://github.com/lspcontainers/lspcontainers.nvim maybe this is a better idea.
- Thoughts on improving security of Neovim plugins
-
Vim users, what additional plugins do you use with vim-go?
I use neovim with the builtin LSP and treesitter. With the lspcontainers plugin I run my langauge server in a docker container and I am very happy with my setup.
-
Pyright, imports and docker
https://www.reddit.com/r/neovim/comments/jiocib/neovim_lsp_and_docker/ https://github.com/lspcontainers/lspcontainers.nvim https://github.com/lspcontainers/lspcontainers.nvim
ua-parser-js
-
Tell HN: Microsoft Teams is blocking Firefox Nightly
Just look at all the big companies doing it
https://faisalman.github.io/ua-parser-js/
-
Liguard - The Linode Guard
This project is backed under MIT License, special shout out to project UA-Parser, as liguard uses a piece of its source-code.
-
Modern PHP
With NPM, what's actually published is not what's in the git repo, so it's harder to inspect/review vulnerabilities or hijacking. With composer, what's in git _is_ what composer pulls (with the exception of rules in .gitattributes to exclude files etc), making it much easier to trace. One such example: https://github.com/faisalman/ua-parser-js/issues/536
Composer packages are vendor namespaced, so hijacking an abandoned package is not possible (and it is with NPM), some examples like https://www.theregister.com/2021/08/10/github_npm_package/
-
Some developers are fouling up open-source software
Sure, I suppose in theory it could happen with other ecosystems, but for some reason it doesn't. It sure seems to just keep happening in NPM though.
-
Vulnerable and Outdated Components
From the other side, npm package may be hijacked(as it happened recently for ua-parser-js and to other packages earlier). To mitigate that, I don't know, probably, subscribing to some security digest would be the most helpful.
- Red Hat response to Java release cadence change
-
Secure software supply chain: why every link matters
On Oct. 22, 2021, developers of a very common NPM package, ua-parser-js, discovered that some attackers uploaded a compromised version of the package containing malware for Linux and Windows, and were capable of stealing data (at least passwords and cookies from the browser).
-
Thoughts on improving security of Neovim plugins
Since Neovim 0.5 release (which has full Lua support) I see more and more amazing Lua plugins being developed, and I think this trend will likely to continue. But I recently got more concerned about security risks associated with the way Neovim plugins being installed and used (especially after seeing recent compromises like ua-parser-js or coa). Installing typical Neovim plugin is basically downloading and executing random code from the internet on your machine with your user privileges, so hijacked or deliberately malicious plugin could potentially do a lot of damage (like stealing keys/passwords, installing keylogger or just rm -rf / for fun).
-
Hidden XMRig miner malware discovered in hijacked versions of popular ua-parser-js npm library
thread about compromise https://github.com/faisalman/ua-parser-js/issues/536
- Malware Discovered in Popular NPM Package, ua-parser-js
What are some alternatives?
nvim-remote-containers - Develop inside docker containers, just like VSCode
react-device-detect - Detect device, and render view according to detected device type.
lsp-ws-proxy - WebSocketify any Language Server
bowser - a browser detector
cscope_maps.nvim - For old school code navigation. Adds cscope support to Neovim 0.9+.
remarkable - Markdown parser, done right. Commonmark support, extensions, syntax plugins, high speed - all in one. Gulp and metalsmith plugins available. Used by Facebook, Docusaurus and many others! Use https://github.com/breakdance/breakdance for HTML-to-markdown conversion. Use https://github.com/jonschlinkert/markdown-toc to generate a table of contents.
firejail - Linux namespaces and seccomp-bpf sandbox
enquirer - Stylish, intuitive and user-friendly prompts, for Node.js. Used by eslint, webpack, yarn, pm2, pnpm, RedwoodJS, FactorJS, salesforce, Cypress, Google Lighthouse, Generate, tencent cloudbase, lint-staged, gluegun, hygen, hardhat, AWS Amplify, GitHub Actions Toolkit, @airbnb/nimbus, and many others! Please follow Enquirer's author: https://github.com/jonschlinkert
telescope-zoxide - An extension for telescope.nvim that allows you operate zoxide within Neovim.
Serilog - Simple .NET logging with fully-structured events
cutlass.nvim - Plugin that adds a 'cut' operation separate from 'delete'
pnpm - Fast, disk space efficient package manager