
Research
/Security News
DuckDB npm Account Compromised in Continuing Supply Chain Attack
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
@tslsmart/font-local-base
Advanced tools
这是仅在私网里面部署的项目需要用到的基础字体库,包含HYQiHei
字体和Plain
字体
使用汉仪旗黑字体后,文字没法垂直居中?
试试给元素添加.font-fix
类名试试!
点击这里查看更多详情
注意,请仅在需要部署到局域网中,无法访问到公网的项目中使用本字体库.
注意,请仅在需要部署到局域网中,无法访问到公网的项目中使用本字体库.
注意,请仅在需要部署到局域网中,无法访问到公网的项目中使用本字体库.
本字体库完整地引入了四种字重的汉仪旗黑字体,因此首屏加载速度会非常慢,如果你的项目能访问到公网的话,请使用更友好的汉仪旗黑字体加载方式
pnpm i @tslsmart/font-local-base
// 入口文件main.js中
import '@tslsmart/font-local-base'
已默认对html标签使用了font-family: "Plain Regular", "HYQiHei";
来设置字体,其余的元素会继承该属性,无需再手动申明该属性
FAQs
We found that @tslsmart/font-local-base demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
Security News
The MCP Steering Committee has launched the official MCP Registry in preview, a central hub for discovering and publishing MCP servers.
Product
Socket’s new Pull Request Stories give security teams clear visibility into dependency risks and outcomes across scanned pull requests.