
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@decantr/ui
Advanced tools
Decantr UI Framework - signal-based reactivity, atomic CSS, 100+ components.
pnpm add @decantr/ui
The package provides multiple entry points:
| Export | Description |
|---|---|
@decantr/ui | Main entry point |
@decantr/ui/runtime | Runtime engine |
@decantr/ui/state | Signal-based state management |
@decantr/ui/state/store | Store primitives |
@decantr/ui/state/arrays | Reactive array utilities |
@decantr/ui/state/devtools | DevTools integration |
@decantr/ui/state/middleware | State middleware |
@decantr/ui/components | Component library (100+ components) |
@decantr/ui/icons | Icon system |
@decantr/ui/router | Client-side routing |
@decantr/ui/data | Data fetching utilities |
@decantr/ui/ssr | Server-side rendering |
@decantr/ui/i18n | Internationalization |
@decantr/ui/form | Form handling |
@decantr/ui/tags | Template tag helpers |
@decantr/ui/tannins/auth | Authentication feature |
@decantr/ui/tannins/telemetry | Telemetry feature |
@decantr/ui/tannins/auth-enterprise | Enterprise auth feature |
@decantr/ui/css | CSS utilities |
@decantr/css - Framework-agnostic CSS atoms runtimeMIT
FAQs
Decantr UI Framework - signal-based reactivity, atomic CSS, 100+ components
We found that @decantr/ui demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.