data:image/s3,"s3://crabby-images/9fef7/9fef7e77a4ff9a4c39b8a32ffd7ebda8c2145888" alt="Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy"
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
@aurodesignsystem/design-tokens
Advanced tools
$ npm i @aurodesignsystem/design-tokens
Located in the ./dist/tokens
directory of the npm.
└── tokens
├── CSSCustomProperties.css
├── CSSSizeCustomProperties.css
├── JSData--color.js
├── JSObject--allTokens.js
├── JSObject--deprecated.js
├── JSVariables--color.js
├── SCSSVariableMap.scss
├── SCSSVariables.scss
├── SCSSVariablesMapFlat.scss
├── SassCustomProperties.scss
├── SassSizeCustomProperties.scss
└── darkmode
├── CSSCustomProperties.css
├── JSDataColor.js
├── JSObject--allDarkTokens.js
├── JSVariablesColor.js
├── SCSSVariables.scss
├── SCSSVariablesMapFlat.scss
└── SassCustomProperties.scss
file | syntax | type | status | filter type / description |
---|---|---|---|---|
CSSCustomProperties | CSS | custom properties | current | full list of v3.0x release tokens |
CSSSizeCustomProperties | CSS | custom properties | current | filter: size, public |
JSData--color | JS module | color data | current | filter: color, current |
JSObject--deprecated | JS module | deprecated tokens | current | filter: deprecated, pubic |
JSObject--allTokens.js | JS module | all data | current | filter: public |
JSVariables--color | js es6 | color data | current | filter: color |
SCSSVariableMap | Sass | Sass variable map | current | filter: size, public |
SCSSVariables | scss | Sass variables | current | full list of v3.0x release tokens |
SCSSVariablesMapFlat | scss | Scss variable map | current | full list of v3.0x release tokens |
SassCustomProperties | scss | custom properties | current | full list of v3.0x release tokens |
SassSizeCustomProperties | Sass | custom properties | current | filter: size, public |
With the release of Auro Design Tokens 4.x a new variable namespace was introduced. The project has removed --auro
and replaced with --ds
. This was done to support upcoming theming capabilities.
Since not all Auro web components are using the new tokens, simply removing the 3.x version and replacing with the 4.x version will break your UI.
To allow for a seamless transition between the two sets of design tokens, we highly recommend the following install supoprt.
@aurodesignsystem/design-tokens@4.x
, but DO NOT uninstall @alaskaairux/design-tokens@3.15.5
.@aurodesignsystem/webcorestylesheets
which fully supports the new token naming spec.By allowing your project to support both the legacy and new Auro design tokens, this will ensure a smooth transition until all Auro components have been updated and your project has also updated local SCSS/CSS files with the new references.
@import "~@aurodesignsystem/design-tokens/dist/tokens/SCSSVariables";
// or
@import "~@aurodesignsystem/design-tokens/dist/tokens/SassCustomProperties";
With React or similar framework, the CSS file can be imported directly from the npm:
import "@aurodesignsystem/design-tokens/dist/tokens/CSSCustomProperties.css"
For other frameworks, it's suggested that the CSS file be copied from the npm into the scope of the project with a build scenario.
Within a webpack supported application or a type="module"
script:
import { AuroColorAlertNotificationOnLight, AuroColorBorderErrorOnLight } from '@aurodesignsystem/design-tokens/dist/tokens/JSVariables--color.js';
Using the https://cdn.jsdelivr.net/npm/
CDN, every file in the dist directory can be accessed like so.
<link rel="stylesheet" href="https://cdn.jsdelivr.net/npm//@aurodesignsystem/design-tokens@latest/dist/tokens/CSSCustomProperties.css">
NOTE: Please use caution when using the CDN solution. We are not responsible for the CDN https://cdn.jsdelivr.net/
uptime and are unable to effectively troubleshoot when there are response issues. It is recommended to use the installed version of Auro Design Tokens when using them in critical UIs.
FAQs
Alaska Air Auro Design System token repository
The npm package @aurodesignsystem/design-tokens receives a total of 2,047 weekly downloads. As such, @aurodesignsystem/design-tokens popularity was classified as popular.
We found that @aurodesignsystem/design-tokens demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.