
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@biom3/design-tokens
Advanced tools


This package publishes via CICD to the public npm component: @biom3/design-tokens. To read more, see the theming & tokenisation proposal document.
To see an overview of the entire design-tokens taxonomy, see this document.
Through this component we expose our complete library of BIOME design tokens. They are made available for use as both:
To use the typescript design-tokens, simply import them from the root of the pacakge. For example:
import { base } from '@biom3/design-tokens';
BIOME's default colour scheme is onLight. Therefore, when you import the base, or onLightBase design-tokens, you will get ONLY the onLight colors and gradients.
To use these design-token variables inside bespoke react typescript components:
import {
onDarkBase,
onLightBase,
smartPickTokenValue,
} from '@biom3/design-tokens';
const DemoComponent = () => (
<div
style={{
fontSize: onLightBase.text.body.medium.regular.fontSize,
color: smartPickTokenValue(onDarkBase, 'base.color.brand.1'),
}}
>
test component text
</div>
);
All the BIOME design-tokens can be imported and used as simple css-variables, by importing css files from your App code. For example:
import '@biom3/design-tokens/css/base-onLight.global.css'; // contains all "onLight" BASE design-tokens
// import "@biom3/design-tokens/css/base-onDark.global.css"; // contains all "onDark" BASE design-tokens
import '@biom3/design-tokens/css/text.global.css'; // contains all fonts (@font-face) imports
*@NOTE All css-variable declarations are global styles scoped to the body selector, thus the base design-token files will overwrite each other, so you should only use 1 base design-token css file at a time. Choose the theme css file based on whether you are planning to display UI in "onDark" or "onLight" (or add your own!).
To see a complete listing of all available design-token css-variables, you can inspect the body element inside your browser's dev tools. For example:

Then, to use these css-variable design-tokens:
/* some custom styles.css file: */
@import '@biom3/design-tokens/css/base-onDark.global.css';
@import '@biom3/design-tokens/css/text.global.css';
/* your bespoke item class styles */
.headingText {
color: var(--base-color-brand-1);
}
FAQs

The npm package @biom3/design-tokens receives a total of 1,000 weekly downloads. As such, @biom3/design-tokens popularity was classified as popular.
We found that @biom3/design-tokens demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.

Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.

Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.