Security News
PyPI’s New Archival Feature Closes a Major Security Gap
PyPI now allows maintainers to archive projects, improving security and helping users make informed decisions about their dependencies.
@elliemae/ds-basic
Advanced tools
ds-basic is a package that used to host a set of basic components in the earlier major versions of dimsum, around the time version 1.37.x and later on with version 3.X.X of dimsum was release dimsum scaffolding have been changed to better fit mono-repos structures and be more compatible with mono-repo tools, as per the dedicated ds-codemods
fix-legacy-imports
& help-migrate-to-v3
scripts, all the import xxx from '@elliemae/ds-basic
statements in the application have been deprecated in favor of dedicated import statements referencing the correct package itself.
In version 3.x.x the ds-basic
package is currently only being used to host scss
styling, the only build scripts of the package itself are dedicated to comply ONLY scss compilation itself and nothing more.
dimsum component that are still using scss
files are either deprecated, soon to be deprecated or are going to be converted to styled-components styling, as such we are going to avoid compiling the scss file on build by default, changes to scss files are too sparse to justify the time-loss on each build/release, we are still going to keep around the logic for compiling the scss just in case, but by default we are not going to re-compile it, we are instead going to just copy-paste the dist file over, since at this point they are more static than dynamic.
Once all the non-deprecated packages lose the scss
styling dependency we will completely remove ds-basic from the library and ds-basic scss would be present only as a deprecated unsupported package hosting scss/css for deprecated/unsupported components.
FAQs
EllieMae UI Design System Library
The npm package @elliemae/ds-basic receives a total of 1,260 weekly downloads. As such, @elliemae/ds-basic popularity was classified as popular.
We found that @elliemae/ds-basic demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
PyPI now allows maintainers to archive projects, improving security and helping users make informed decisions about their dependencies.
Research
Security News
Malicious npm package postcss-optimizer delivers BeaverTail malware, targeting developer systems; similarities to past campaigns suggest a North Korean connection.
Security News
CISA's KEV data is now on GitHub, offering easier access, API integration, commit history tracking, and automated updates for security teams and researchers.