
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@postscript/components
Advanced tools
The main branch is used to create a Storybook instance at components.postscript.io, via Chromatic.
This repo generates an NPM package of components. Use components by importing them individually.
npm i @postscript/components
import { Button } from '@postscript/components';
const App = () => <Button>A Happy Button</Button>;
Import our base CSS once in your project.
import '@postscript/components/dist/esm/main.css';
Currently, the easiest way to test changes from a feature branch in another repo is to publish a one-off, unique version of the package under a tag specific to you. View instructions
Commits to main will publish a new @postscript/components package version. Use one of the following conventions when commiting/titling PRs to control semantic versioning.
BREAKING CHANGE: prefix to the commit message (bumps the major version X.#.#)feature: or feat: prefix to your commit message (bumps the minor version #.Y.#)#.#.Z)Follow your commits to postscript-frontend, and address any changes needed to bump version.
PRs require one engineer approval. If working with a designer, tag them as well. Directly requesting review from those with good knowledge of your changes is helpful if they're available.
Additionally, post for review in #pull-requests and #front-end.
We utilize SVGR CLI to turn SVGs into React components. See .svgrrc.js for our
config.
src/icons/npm run svgrimport * as React from 'react'; to the new module(s)src/icons/index.ts; IconSet uses this barrelIcon story examples automatically if everything has worked correctlyWe utilize the following automatic transformations.
Create your component with Typescript, its corresponding Storybook file, and a unit test file.
!! Be sure to add your new component to the exports list in src/index.ts and organize its display order in .storybook/preview.js
FAQs
Postscript Component Library
The npm package @postscript/components receives a total of 1,109 weekly downloads. As such, @postscript/components popularity was classified as popular.
We found that @postscript/components demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 16 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.