
Security News
OWASP 2025 Top 10 Adds Software Supply Chain Failures, Ranked Top Community Concern
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.
github.com/lyne-design-system/lyne-components
Advanced tools
Lyne Components are the building blocks of the Lyne Design System and are based on standard compliant Web Components created using Lit and browsable through Storybook
To fulfill our Vision, we are building and maintaining Lyne, our Design System, which is and acts as our common language — our Single Source of Truth. For this purpose we use Design Tokens as our design abstractions. Those Design Tokens are consumed by Lyne Components and are integrated within our documentation.
Lyne Design Tokens and Lyne Components are available for developers and designers.
| Package | Description |
|---|---|
@sbb-esta/lyne-elements | Web components built on top of the Lyne Design System |
@sbb-esta/lyne-elements-experimental | Web components that do not yet align with our architecture or testing goals |
@sbb-esta/lyne-react | React wrappers for @sbb-esta/lyne-elements |
@sbb-esta/lyne-react-experimental | React wrappers for @sbb-esta/lyne-elements-experimental |
This library supports the most recent two versions of all major browsers: Chrome (including Android), Firefox, Safari (including iOS), and Edge.
We aim for great user experience with the following screen readers:
Windows: NVDA and JAWS with FF / Chrome. macOS: VoiceOver with Safari / Chrome. iOS: VoiceOver with Safari Android: Android Accessibility Suite (formerly TalkBack) with Chrome.
This software is published by SBB-CFF-FFS under the MIT licence and unsupported unless otherwise clearly stated. Use at your own risk.
FAQs
Unknown package
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.