
Security News
pnpm 10.16 Adds New Setting for Delayed Dependency Updates
pnpm's new minimumReleaseAge setting delays package updates to prevent supply chain attacks, with other tools like Taze and NCU following suit.
@envato-foundation/foundation-design-system
Advanced tools
Foundation Design System is a collection of design tokens, components and guidelines for building cohesive UI systems within parts of Envato.
Status: Work in Progress.
In order to set up the project locally follow these steps:
git clone git@github.com:envato/foundation-design-system.git
npm i
npm start
The project has been bootstrapped with Create React App and the following files must exist in order to build the sites correctly:
index.html
: the page templatesrc/favicon.ico
: the icon representing the site in the browser tabsrc/index.js
: the JavaScript entry point.Remember to always base your feature branch off of master
.
Read the Publishing guide on how to version and publish modules to NPM.
Read the How to Use Guide for possible installation options for the Foundation Design System within your project.
Read our Creating Design Tokens Guide.
Please familiarise yourself with our Contributing Guidelines to make the contribution process easy and effective for everyone involved.
This project adheres to the Contributor Covenant Code Of Conduct. By participating, you are expected to uphold this code. Please report unacceptable behavior to market-foundation-dev@envato.com.
FAQs
Envato foundation design system
We found that @envato-foundation/foundation-design-system demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm's new minimumReleaseAge setting delays package updates to prevent supply chain attacks, with other tools like Taze and NCU following suit.
Security News
The Rust Security Response WG is warning of phishing emails from rustfoundation.dev targeting crates.io users.
Product
Socket now lets you customize pull request alert headers, helping security teams share clear guidance right in PRs to speed reviews and reduce back-and-forth.