Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
@sendbird/uikit-react
Advanced tools
Sendbird UIKit for React: A feature-rich and customizable chat UI kit with messaging, channel management, and user authentication.
React based UI kit based on sendbird javascript SDK
We are introducing a new version of the Sendbird Chat UIKit. Version 3 features a new modular architecture with more granular components that give you enhanced flexibility to customize your web and mobile apps. Check out our migration guides.
yarn add @sendbird/uikit-react
or if you're using npm
npm i @sendbird/uikit-react
With Sendbird UI Kit React, we export these components:
(See src/index.jsx
)
SendBirdProvider - The context provider for SDK component
useSendbirdStateContext - Hook to access SendBirdProvider context
sendBirdSelectors - A bunch of useful selectors that can be used along with useSendbirdStateContext
Channel - A UI Component where conversations happen
ChannelList - A ChannelList UI component
ChannelSettings - A component to handle the settings of a given channel
MessageSearch - To search for a message from a Channel
OpenChannel - A UI Component where open channel conversations happen
OpenChannelSettings - A component to handle the settings of a given channel And many more...
App - is a full fledged app(group channel) component made by combining the above components so that you dont have to combine all the above components by hand. Also it can be used as an example for composing components to build a chat UI
Note 1: Dont forget to import the stylesheet from the repo too Note 2: Name of some components are different from the directories they are in(example -> Channel component is from Conversation component). Please keep that in mind
You need to install:
We use vite app for development and rollup for building the npm distribution(bundled JS file) Make sure you have nodejs and yarn installed and run
Make a copy of
apps/testing/.env.example
and save it asapps/testing/.env
Set your appId toVITE_APP_ID
yarn install
yarn dev
We provide a Storybook to easily view and understand the components.
https://sendbird.github.io/sendbird-uikit-react/
yarn storybook
We use RollupJS for building the production bundle script that you want to use inside your applications.
We have both ESM
and CJS
output
yarn build
The bundled JS code can be found in ./dist
The CSS is in ./dist/dist/index.css
Caveats
yarn build
in Windows machinesWe have implemented tests for dumb ui components only. Technologies used: Jest and testing-library
yarn test
yarn lint
./src
../rollup.module-exports.js
:
'NewComponent/SubComponent': 'location/of/NewComponent/SubComponent',
import SubComponent from '@sendbird/uikit-react/NewComponent/SubComponent';
yarn run generate-component
to generate a UI component in src/ui
. It uses Plop.js to generate the component.We use lamejs for converting audio formats It is a fast mp3 encoder written in JavaScript. The original repo is:
FAQs
Sendbird UIKit for React: A feature-rich and customizable chat UI kit with messaging, channel management, and user authentication.
The npm package @sendbird/uikit-react receives a total of 21,153 weekly downloads. As such, @sendbird/uikit-react popularity was classified as popular.
We found that @sendbird/uikit-react demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.