
Security News
/Research
Popular node-ipc npm Package Infected with Credential Stealer
Socket detected malicious node-ipc versions with obfuscated stealer/backdoor behavior in a developing npm supply chain attack.
@nullserve/react-lib
Advanced tools
This project houses a react component library utilized by NullServe React apps. It acts both as a library and rudimentary design system.
There are 3 primary frameworks in use in this project:
Create React Library and Storybook detect and utilize Create React App and to help deliver their independent goals.
It's recommended that storybook be used for local development. Storybook will allow you to write use cases to visually test and demonstrate a component use case.
yarn run storybook
NullServe's component system is driven primarily by Chakra UI for style and layout. While Apollo Client is generally assumed to exist, it isn't brought in by this library or used by any pages at this time. Formik and Yup are used for form components and validation. Reach Router is used for routing.
In the future, these dependencies may be moved to a different library and this project may be changed over to a monorepo that houses them, to try to isolate transitive dependencies. If you're reading this and that sounds like something you want, open a github issue.
FAQs
Made with create-react-library
The npm package @nullserve/react-lib receives a total of 21 weekly downloads. As such, @nullserve/react-lib popularity was classified as not popular.
We found that @nullserve/react-lib demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
Socket detected malicious node-ipc versions with obfuscated stealer/backdoor behavior in a developing npm supply chain attack.

Security News
TeamPCP and BreachForums are promoting a Shai-Hulud supply chain attack contest with a $1,000 prize for the biggest package compromise.

Security News
Packagist urges PHP projects to update Composer after a GitHub token format change exposed some GitHub Actions tokens in CI logs.