
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
@guardian/atoms-rendering
Advanced tools
An Atom is a self contained piece of content that can be inserted into multiple articles. There are currently 13 types of atoms. This repository implements them as a separate self contained library.
To import an atom in your project use yarn add @guardian/atoms-rendering
then
import { TheAtomYouWant } from '@guardian/atoms-rendering';
<TheAtomYouWant someProp={localData.someProp} />
There is mostly a one to one correspondance between atoms as named by CAPI/frontend and their names in atoms-rendering, with the notable exception that the Media atom is named YoutubeAtom here.
The master
branch in the atoms-rendering repository has now been renamed to main
. If you have been working with this repository before the change, then run the following sequence of commands.
git fetch --all
git remote set-head origin -a
git branch master --set-upstream-to origin/main
git branch -m master main
$ git clone https://github.com/guardian/atoms-rendering.git
or
$ git clone git@github.com:guardian/atoms-rendering.git
Make sure that you have yarn
installed, if not run
$ brew install yarn
Then,
$ yarn
$ yarn storybook
The available yarn commands are given below:
"scripts": {
"build": "microbundle --jsx React.createElement",
"dev": "microbundle watch --jsx React.createElement",
"storybook": "start-storybook -p 6006",
"build-storybook": "build-storybook",
"tsc": "tsc",
"lint": "eslint . --ext .ts",
"test": "jest --watch"
}
If you want to test a change before publishing to NPM, you will need to point to this repository. For instance, you might want to check in dotcom-rendering on local that a change you make in this library is correct. For this do the following
yarn build
,yarn link
, thenyarn link "@guardian/atoms-rendering"
.Then you will notice that your
dotcom-rendering/node_modules/@guardian/atoms-rendering
is a symlink to the atoms-rendering repository.
When you are done, you should
yarn unlink "@guardian/atoms-rendering"
.yarn unlink
And in dotcom-rendering you might also want to run
yarn install --force
, to get the regular package re-installed.Adding a new atom in atoms-rendering
involves
index.ts
to export the componentManual publishing steps:
yarn build
yourname/v1.0.1
yarn publish
(enter new version number, eg. 1.0.1)@guardian/atoms-rendering
installed to see the changesFAQs
Unknown package
The npm package @guardian/atoms-rendering receives a total of 4 weekly downloads. As such, @guardian/atoms-rendering popularity was classified as not popular.
We found that @guardian/atoms-rendering demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 44 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.