Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@carto/airship
Advanced tools
Airship is a components library built by CARTO
There are three npm packages for easier use:
module | status | version | description |
---|---|---|---|
airship-style | A complete CSS framework to build location intelligence apps. | ||
airship-components | Web components for Location Intelligence apps. | ||
airship-icons | High quality icons set |
Check out our documentation website
We're currently changing the approach of Airship. After gathering feedback from several partners and users, we are recoding the widgets as Web Components and providing a CSS framework for layout and simple components. In our tests this has been easily integrated with React, Angular or vanilla and will help us to broaden our partners support. A React components-only library has not worked as well as we thought initially.
That means that this alpha version of Airship made with React is in a stale branch and no further development on React is expected. Feel free to fork that branch and make whatever change you need in case you need the widgets as React components.
Sorry for the inconveniences.
BSD-3-Clause, see the included LICENSE.md file.
FAQs
CARTO Airship framework
The npm package @carto/airship receives a total of 18 weekly downloads. As such, @carto/airship popularity was classified as not popular.
We found that @carto/airship demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 20 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.