Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@patreon/studio
Advanced tools
Studio Design System is Patreon’s web design system and is built with React and Styled Components and written in Typescript.
The docs for Studio Design System live at https://studio.patreon.com
npm i -P @patreon/studio
View available Studio components and how to use them in the docs.
Run npm run dev
and open localhost:6006
in your browser. This will start Storybook and watch for changes.
Run npm run test
or npm run test:watch
If you make changes to a component and the snapshot test fails, you can update the snapshot by running npm run test:ci -- -u
or npm run test:ci -- [file] -u
for a specific snapshot file.
Happo is our tool for visual regression testing. It's integrated as part of our CircleCI tests, but can also be run locally, with a little bit of setup:
.env
file in the studio
directory (it will be ignored by git)npm install
to make sure dependencies are installed (dotenv
in particular).npm run happo dev
, which will watch files for changes and with the --only
flag can be limited to specific components. See the docs for more info.If you don't already have a PRF container in rdev, create one:
rdev new patreon_react_features --name prf
Open an SSH session to your container:rdev ssh prf
Inside your container, install Studio in the home directory
cd /home/dev
git clone git@github.com:Patreon/studio.git
Run the same instructions as above:
cd studio
npm install
npm run prf:link
Run npm run prf:unlink
to revert to the published version of Studio.
FAQs
Patreon Studio Design System
The npm package @patreon/studio receives a total of 95 weekly downloads. As such, @patreon/studio popularity was classified as not popular.
We found that @patreon/studio demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 16 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.