
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
@arijs/naive-ui
Advanced tools
A Vue 3 Component Library. Fairly Complete, Customizable Themes, Uses TypeScript, Not Too Slow
A Vue 3 Component Library
Fairly Complete, Customizable Themes, Uses TypeScript, Not too Slow
Kinda Interesting
English | 中文
There are more than 70 components. Hope they can help you write less code.
What's more, they are all treeshakable.
We provide an advanced type safe theme system built using TypeScript. All you need is to provide a theme overrides object in JS. Then all the stuff will be done by us.
What's more, no less/sass/css variables, no webpack loaders are required.
All the stuff in Naive UI is written in TypeScript. It can work with your typescript project seamlessly.
What's more, you don't need to import any CSS to use the components.
I try to make it not rather slow. At least select, tree, transfer, table and cascader work with virtual list.
What's more, ..., no more. Just enjoy it.
Use npm to install.
npm i -D naive-ui
npm i -D vfonts
Naive UI recommends using xicons as icon library.
Please see CONTRIBUTING.md.
Naive UI is licensed under the MIT license.
Graphics resouces of result
component is licensed under the CC-BY 4.0. The graphics resources come from Twemoji.
FAQs
A Vue 3 Component Library. Fairly Complete, Customizable Themes, Uses TypeScript, Not Too Slow
The npm package @arijs/naive-ui receives a total of 0 weekly downloads. As such, @arijs/naive-ui popularity was classified as not popular.
We found that @arijs/naive-ui demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.