
Research
npm Malware Targets Telegram Bot Developers with Persistent SSH Backdoors
Malicious npm packages posing as Telegram bot libraries install SSH backdoors and exfiltrate data from Linux developer machines.
@leafygreen-ui/icon-button
Advanced tools
yarn add @leafygreen-ui/icon-button
npm install @leafygreen-ui/icon-button
import IconButton from '@leafygreen-ui/icon-button';
<IconButton variant="light" aria-label="Some Menu">
<Icon glyph="Ellipsis" />
</IconButton>;
Output HTML
<button aria-disabled="false" class="leafygreen-ui-194rp0y" aria-label="Some Menu>
<div class="leafygreen-ui-1rvdyoi">
<svg width="16px" height="16px" viewBox="0 0 16 16" version="1.1">
<g
id="Ellipsis-Copy"
stroke="none"
stroke-width="1"
fill="none"
fill-rule="evenodd"
>
<path fill="#89989B"></path>
</g>
</svg>
</div>
</button>
Prop | Type | Description | Default |
---|---|---|---|
variant | 'dark' or 'light' | Sets the style variant of the button. | 'light' |
onClick | function | The event handler function for the 'onclick' event. Receives the associated event object as the first argument. | |
disabled | boolean | Disables the <IconButton /> | false |
href | string | If a href is supplied, the component renders inside of an a tag instead of inside of a button tag. | |
className | string | Adds a className to the class attribute on the container element. | |
children | node | Content rendered inside of the <IconButton /> component | |
size | default , large , xlarge | Determines the size of the IconButton | default |
active | boolean | Determines whether the <IconButton /> will appear active | false |
Either aria-label
or aria-labelledby
must be provided a string, or there will be a console error. This is to ensure that screenreaders have a description for what the button does, since the button itself doesn't contain any text.
Any other properties will be spread on the container element.
FAQs
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Malicious npm packages posing as Telegram bot libraries install SSH backdoors and exfiltrate data from Linux developer machines.
Security News
pip, PDM, pip-audit, and the packaging library are already adding support for Python’s new lock file format.
Product
Socket's Go support is now generally available, bringing automatic scanning and deep code analysis to all users with Go projects.