Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
@fluentui/react-file-type-icons
Advanced tools
File type icons for Fluent UI React (formerly Office UI Fabric React)
This package includes a collection of icons to represent file types.
If you are using Fluent UI React components, you can make all file type icons available by calling the initializeFileTypeIcons
function from the @fluentui/react-file-type-icons
package:
import { initializeFileTypeIcons } from '@fluentui/react-file-type-icons';
// Register icons and pull the fonts from the default Microsoft Fluent CDN:
initializeFileTypeIcons();
// Or register icons and pull the fonts from a different CDN or folder path:
initializeFileTypeIcons('https://my.cdn.com/path/to/icons/');
NOTE: Proceed carefully if you override the default CDN location, whose contents may not match the registered file type icons and supported extensions. Do not use the item-types-fluent
icon set that was previously uploaded to the Fluent CDN; it's deprecated.
If you are using Fluent UI React, you can use the Icon
component and pass in the corresponding icon properties to render a given icon.
import { Icon } from '@fluentui/react/lib/Icon';
import { getFileTypeIconProps } from '@fluentui/react-file-type-icons';
<Icon {...getFileTypeIconProps({ extension: 'docx', size: 16 })} />;
See GitHub for more details on the Fluent UI React project and packages within.
FAQs
Fluent UI React file type icon set.
The npm package @fluentui/react-file-type-icons receives a total of 13,391 weekly downloads. As such, @fluentui/react-file-type-icons popularity was classified as popular.
We found that @fluentui/react-file-type-icons demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.