
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@civicactions/cmsds-open-data-components
Advanced tools
Components for the open data catalog frontend using CMS Design System
This repo acts as an upstream common react library for CMS Open Data sites. This library is powered by Parcel.
For local development, we recommend using npm workspaces. Once you have a workspace directory, install this library inside your workspace along any Open Data downstream sites you wish to work on.
In the root folder for this project, run npm run watch
to build local code. Ensure the upstream is using the same version number located in package.json of this repo. Start the upstream site locally as well, and it should load local code from this repo as the dependency. Parcel also provides hot rebuilding while watch
is running.
Run npm run build
to create a production version of the library before publishing to npm.
Run npm publish
to publish to npm
Jest tests can be run using:
npm run test
FAQs
Components for the open data catalog frontend using CMS Design System
The npm package @civicactions/cmsds-open-data-components receives a total of 132 weekly downloads. As such, @civicactions/cmsds-open-data-components popularity was classified as not popular.
We found that @civicactions/cmsds-open-data-components demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.