
Research
/Security News
DuckDB npm Account Compromised in Continuing Supply Chain Attack
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
This is a library of React components that are used in the PINAX ecosystem. It's built on top of multiple frameworks & tools.
The goal of the library is to be strict in its design and implementation, while also being flexible enough to be used in a variety of projects. It leverages conventions from major UI libraries such as MUI, while removing a lot of boilerplate and complexity. Effectively trading off some flexibility for simplicity, while remaining familiar.
$ npm install @pinax/ui
import React from "react";
import { Button } from "@pinax/ui";
import { BlogIcon } from "@pinax/ui/icons";
function handleClick() {
console.log("Clicked!");
}
export default () => (
<Button onClick={handleClick} startIcon={<BlogIcon />}>
Click Me
</Button>
);
Accordion
Avatar
Backdrop
Badge
Button
Card
Checkbox
Chip
Code
CodeSnippet
Confetti
Container
Copyright
Divider
Dropdown
Grid
Icon
Input
Link
Loading
Modal
Pagination
Progress
RadioGroup
Slider
Snackbar
Switch
Table
Tabs
Tooltip
User
AnalyticsIcon
BillingIcon
BlogIcon
CaretDownIcon
CaretLeftIcon
CaretRightIcon
CaretUpIcon
CopyIcon
CoreIcon
DeleteIcon
DiscordIcon
DocsIcon
ExternalLinkIcon
FirehoseIcon
FirstPageIcon
GatewayIcon
GithubIcon
GraphIcon
HamburgerIcon
HiddenIcon
InternalLinkIcon
LastPageIcon
LinkIcon
LinkedinIcon
MailIcon
NewIcon
NftIcon
PinaxIcon
RecentIcon
SearchIcon
SortAscendingIcon
SortDescendingIcon
SortIcon
SubstreamsIcon
TimeseriesIcon
TokenIcon
TwitterIcon
UploadIcon
UserIcon
VideoIcon
VisibleIcon
WebhookIcon
YoutubeIcon
$ npm run build
$ storybook build
$ storybook dev -p 6006
$ bun test
FAQs
Pinax UI Library
We found that @pinax/ui demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
Security News
The MCP Steering Committee has launched the official MCP Registry in preview, a central hub for discovering and publishing MCP servers.
Product
Socket’s new Pull Request Stories give security teams clear visibility into dependency risks and outcomes across scanned pull requests.