
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
@progress/wct-a11y-spec
Advanced tools
Contains accessibility and keyboard navigation specification of Telerik and Kendo web components.
This package contains the WAI-ARIA and Keyboard Navigation spec for the UI suites in the Progress Web Components and Tools division: Kendo UI for Angular, Kendo UI for jQuery, Kendo React, Kendo UI for Vue, Telerik UI for Blazor, Telerik UI for ASP.NET Core (Kendo jQuery based), and Telerik UI for ASP.NET MVC (Kendo jQuery based).
The specifications are published in a npm package:
https://www.npmjs.com/package/@progress/wct-a11y-spec.
All teams can navigate through the generated accessibility specifications via the following link and the respective technology:
https://unpkg.com/browse/@progress/wct-a11y-spec@latest/dist/
To generate the WAI-ARIA specification in MD format for each of the suites, you will need to:
npm installnpm run aria-angularnpm run aria-blazornpm run aria-jquerynpm run aria-reactnpm run aria-vueFor the specifications of all suites call: npm run aria.
The generate MD files will be placed in the following folders:
/dist/angular/aria//dist/blazor/aria//dist/jquery/aria//dist/react/aria//dist/vue/aria/To generate the ARIA test definitions in JSON format for each of the suites, you will need to:
npm installnpm run test-def-angularnpm run test-def-blazornpm run test-def-jquerynpm run test-def-reactnpm run test-def-vueFor the specifications of all suites call: npm run test-def.
The generate JOSN file will be found here:
/dist/angular/test-def/test-definitions.json/dist/blazor/test-def/test-definitions.json/dist/jquery/test-def/test-definitions.json/dist/react/test-def/test-definitions.json/dist/vue/test-def/test-definitions.jsonTo generate the keyboard navigation specification in MD format for all suites call: npm run keyboard.
The generate MD files will be placed in the following folders:
/dist/angular/keyboard-navigation//dist/blazor/keyboard-navigation//dist/jquery/keyboard-navigation//dist/react/keyboard-navigation//dist/vue/keyboard-navigation/FAQs
Contains accessibility and keyboard navigation specification of Telerik and Kendo web components.
We found that @progress/wct-a11y-spec demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.