
Research
/Security News
Weaponizing Discord for Command and Control Across npm, PyPI, and RubyGems.org
Socket researchers uncover how threat actors weaponize Discord across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.
@hugeinc/carousel
Advanced tools
A carousel that'll use CSS to dynamically adapt its width. Uses transforms for its transitions and is also touch-enabled.
The general idea is that this component should maintain a separation of state and style. That is to say, the Javascript maintains the state of the carousel (which slide, etc), while the CSS should take care of the presentation of this state (ie. transitions between slides, responsive, etc).
Features a touch-based interface, simple API, and a very-lightweight footprint. It does the basics well, but that's it. No bloat. You can swipe to drag a slide yet still use CSS to control how the slide transitions will behave. You can also choose to change slides by using the exposed API. The carousel works on both desktop and mobile, while only weighing in at 2.5 KB!
There is an ES6 module you may consume however you wish. Alternatively, you can also include the relevant scripts in your web page, and then:
<!-- sample carousel markup -->
<div class="carousel">
<ul class="wrap"> <!-- slideWrap -->
<li>slide 1</li> <!-- slide -->
<li>slide 2</li>
<li>slide 3</li>
</ul>
</div>
// available options
var options = {
onSlide: someFunction,
activeClass: 'active',
slideWrap: 'ul',
slides: 'li',
infinite: true,
display: 1,
disableDragging: false,
initialIndex: 0
};
var container = document.querySelector('.carousel');
var carousel = new Carousel(container, options);
name | type | default | description |
---|---|---|---|
onSlide | function | undefined | A function to execute on slide. It is passed to and from indices. |
slideWrap | string | ul | The selector to use when searching for the slides' container. This is used only to bind touch events to, on mobile. |
slides | string | li | The selector to use when searching for slides within the slideWrap container. |
activeClass | string | active | Class to use on the active slide. |
animateClass | string | animate | Class to use on the wrapper when animating. |
infinite | boolean | true | Enable an infinitely scrolling carousel or not |
display | integer | 1 | the maximum # of slides to display at a time. If you want to have prev/next slides visible outside those currently displayed, they'd be included here. |
disableDragging | boolean | false | if you'd like to disable the touch UI for whatever reason |
initialIndex | integer | 0 | which slide it's going to start on |
method | description |
---|---|
next() | Advances carousel to the next slide |
prev() | Move carousel to the previous slide |
to(i) | Advance carousel to the ith slide |
destroy() | Destroy carousel and remove all EventListeners |
After cloning the repo:
npm i
npm start
A server will spin up at http://localhost:8080
, where you may play with the various examples. See the "demo" directory.
FAQs
A micro, responsive, touch-enabled carousel.
We found that @hugeinc/carousel demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Socket researchers uncover how threat actors weaponize Discord across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.
Security News
Socket now integrates with Bun 1.3’s Security Scanner API to block risky packages at install time and enforce your organization’s policies in local dev and CI.
Research
The Socket Threat Research Team is tracking weekly intrusions into the npm registry that follow a repeatable adversarial playbook used by North Korean state-sponsored actors.