
Security News
OWASP 2025 Top 10 Adds Software Supply Chain Failures, Ranked Top Community Concern
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.
@ridi/rsg
Advanced tools
Ridi Style Guide. Includes common style assets used in Ridibooks store. https://rsg.ridicorp.com/
Install dependencies
$ yarn install
Run component explorer
$ yarn build:watch
$ yarn storybook
or
$ yarn styleguide
You can import lessfile and override font path variable.
@import "less/ridi-icon.less";
@ridi-iconfont-path: "customPath/";
You can import lessfiles and override path variables for iconfont and image sources.
@import "less/rui.less";
@ridi-iconfont-path: "customPathToIconfontFolder/";
@rui-images-path: "customPathToImagesFolder/";
If any tag is pushed to master branch,
the package is published to NPM automatically by Travis CI.
There is an issue that Travis CI does not report deploy failure. So we should manually check the failure in Travis CI's console if the package is not updated on NPM after the deploy process is finished.
FAQs
Common style assets for Ridibooks
The npm package @ridi/rsg receives a total of 7 weekly downloads. As such, @ridi/rsg popularity was classified as not popular.
We found that @ridi/rsg demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 12 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.