
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@finodigital/uba-widget
Advanced tools
A standalone web component that embeds the fino Universal Bank Access (UBA) experience via a hardened iframe integration. It exposes a declarative HTML API, a small JavaScript controller, and utilities for lazy loading the bundle from a CDN.
<fino-uba> custom element with shadow-dom encapsulated iframeelement.readyUbaWidgetControllernpm install @finodigital/uba-widget
import { createUbaWidget } from "@finodigital/uba-widget";
const controller = createUbaWidget({
sessionId: "<jwt>",
userIdentifier: "<hash>",
hideHeader: true
});
document.querySelector("#uba-container")?.append(controller.element);
controller.on("ready", ({ payload }) => {
console.log("UBA ready", payload.version);
});
<fino-uba
session-id="<jwt>"
user-identifier="<hash>"
tenant="none"
embedded="true"
hide-header
></fino-uba>
<script type="module">
import "@finodigital/uba-widget";
const widget = document.querySelector("fino-uba");
widget?.addEventListener("bank-connect", event => {
console.log("Bank connected", event.detail.payload);
});
</script>
import { loadUbaWidget } from "@finodigital/uba-widget/loader";
await loadUbaWidget({ version: "0.1.0" });
Inside a native WebView the bank login usually has to run in the system browser, which cannot hand its result back to the widget directly. Declare that before importing the widget:
<script>
window.UBA_NATIVE = { platform: "ios", transport: "session-pull", supportsSharedPopup: false };
</script>
<script type="module" src="/path/to/@finodigital/uba-widget"></script>
Set the global from a classic script, or with a dynamic await import(…). A static
import declaration is hoisted and runs before any statement next to it, so
window.UBA_NATIVE = …; import "…" in one module block assigns the global too late —
the element upgrades and reads the contract first.
The widget forwards this contract onto the iframe URL — no other change is needed on the web side. UBA then polls the backend session for the bank result and keeps the account selection inside the widget.
Your native shell still has to do two things: intercept the bank URL (the widget's iframe opens it with window.open) and open it in the system browser, then bring the user back when the widget emits handle-redirect:
widget.addEventListener("handle-redirect", () => nativeBridge.dismissExternalBrowser());
The full guide, including per-platform interception examples, is published at uba.fino.run/public/docs/native-integration.
npm run build – generates ESM and CJS outputs plus type declarations in dist/npm run clean – removes build artifactspackage.jsonnpm run buildFAQs
Standalone web component that embeds the fino UBA experience
The npm package @finodigital/uba-widget receives a total of 25 weekly downloads. As such, @finodigital/uba-widget popularity was classified as not popular.
We found that @finodigital/uba-widget demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.