
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@lacework/react-widgets-fork
Advanced tools
An à la carte set of polished, extensible, and accessible inputs built for React
This could be a single script in package.json, but I figured being explicit is better to catch issues. And we will probably never release another version.
Build for production
npm run build
Bump the version number. This uses the preid format so we have an obvious link to the source docs and code if neede
npm version prerelease --no-git-tag-version
Publish
npm publish --access public --tag latest
Commit and push changes to package-lock.json and package.json
An à la carte set of polished, extensible, and accessible form inputs built for React, based on the excellent Kendo UI Core and jQuery UI.
Pick and choose one, or more of the following Components
Demos and Documentation here
npm install react-widgets
The docs are a simple React app hosted on gh-pages, you build and run locally with the command npm run docs and open up http://localhost:8080/docs/index.htm#/
Patches welcome! Please try to match the style of the repo (comma first, 2 spaces, etc), squash large pull requests (a few commits is fine), and provide tests if relevant. It is also a good idea to open an issue and start a conversation before implementing new features or widgets.
The goal is to support IE8+, but currently it is difficult for me to test a wide variety of browsers so there is no guarantee it will work (patches welcome!).
FAQs
An à la carte set of polished, extensible, and accessible inputs built for React
We found that @lacework/react-widgets-fork demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.