
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
org.webjars.npm:github-com-lipis-flag-icons
Advanced tools
A curated collection of all country flags in SVG — plus the CSS for easier integration. See the demo.
You can either download the whole project as is or install it via npm or Yarn:
npm install --dev flag-icons
# or
yarn add --dev flag-icons
For using the flags inline with text add the classes .fi and .fi-xx (where xx is the ISO 3166-1-alpha-2 code of a country) to an empty <span>. If you want to have a squared version flag then add the class fis as well. Example:
<span class="fi fi-gr"></span> <span class="fi fi-gr fis"></span>
You could also apply this to any element, but in that case you'll have to use the fib instead of fi and you're set. This will add the correct background with the following CSS properties:
background-size: contain;
background-position: 50%;
background-repeat: no-repeat;
Which means that the flag is just going to appear in the middle of an element, so you will have to set manually the correct size of 4 by 3 ratio or if it's squared add also the flag-icon-squared class.
Run the yarn to install the dependencies after cloning the project and you'll be able to:
To build *.less files
$ yarn build
To serve it on localhost:8000
$ yarn start
To have only specific countries in the css file, remove the ones that you don't need from the flag-icons-list.less file and build it again.
flag-icons name on npm.FAQs
WebJar for flag-icons
We found that org.webjars.npm:github-com-lipis-flag-icons demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.