
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@heroku/react-hk-components
Advanced tools
Reusable React components. A sister library of ember-hk-components.
Usage of these components assumes you are using the Purple3 CSS framework and Malibu.
yarn add @heroku/react-hk-components
See react-hk-components.herokuapp.com for a complete list of components that are available.
git clone https://github.com/heroku/react-hk-components
cd react-hk-components
yarn
yarn storybook
The demo app is useful for developing this addon, but it can often be
helpful to consume your version of this addon in another application
either to more easily develop your changes or to validate that your
changes work as you expect. You can use your local version of
react-hk-components
in another application that consumes it via
yarn's link command.
# in your react-hk-components directory
$ yarn link
# in your consuming app directory
$ yarn link @heroku/react-hk-components
Now, when you make changes in your copy of react-hk-components
those
changes will be reflected in the consuming application.
This repo can be deployed to Heroku as a demo app using Storybook.
heroku create
# ensure that heroku installs the dev dependency storybook
heroku config:set NPM_CONFIG_PRODUCTION=false
git push heroku master
FAQs
React components for Heroku
The npm package @heroku/react-hk-components receives a total of 24 weekly downloads. As such, @heroku/react-hk-components popularity was classified as not popular.
We found that @heroku/react-hk-components demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 221 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.