
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@usefillo/dom
Advanced tools
Docs · Guides · Examples · Changelog
Framework-agnostic DOM renderer, web component, and standalone browser bundle for Fillo — forms that render inside your own product, no iframe. Use it with Vue, Svelte, Astro, or plain browser JavaScript.
npm i @usefillo/dom
import { renderForm } from "@usefillo/dom";
import "@usefillo/dom/styles.css"; // optional default theme — or bring your own
renderForm("#fillo-form", {
formId: "cust-feedback",
onSubmitted: (id) => console.log("response", id),
});
Published formId embeds can fetch and submit without a publishable key. Use createClient({ key }) only when syncing code-defined schemas, or when you need to point the SDK at a custom API origin.
import { createClient, defineForm, renderForm } from "@usefillo/dom";
const client = createClient({ key: "pk_…" }); // Settings → Code-defined forms
const form = defineForm({
id: "cust-feedback",
pages: [{ id: "p1", blocks: [
{ id: "email", kind: "email", label: "Work email", required: true },
{ id: "msg", kind: "long_text", label: "What should we know?" },
] }],
});
renderForm("#fillo-form", {
form,
client,
onSubmitted: (id) => console.log("response", id),
});
Or drop it in with a single script tag — the bundle exposes a global Fillo:
<div id="fillo-form"></div>
<script src="https://unpkg.com/@usefillo/dom/dist/standalone.global.js"></script>
<script>
const client = Fillo.createClient({ key: "pk_…" });
const form = Fillo.defineForm({ id: "cust-feedback", pages: [/* … */] });
Fillo.renderForm("#fillo-form", { form, client });
</script>
The default stylesheet follows system dark mode for unthemed embeds. Pass theme: { colorScheme: "dark" } or "light" when the host surface is known.
Every rendered part carries data-* state attributes (data-selected, data-invalid, …) for utility CSS, and the default stylesheet is cascade-layered so your own styles win. On Tailwind v3 or reset-heavy sites import @usefillo/dom/styles.unlayered.css instead. Styling contract: fillo.so/docs/styling.
MIT licensed.
FAQs
Framework-agnostic DOM renderer and web component for embedding Fillo forms.
The npm package @usefillo/dom receives a total of 480 weekly downloads. As such, @usefillo/dom popularity was classified as not popular.
We found that @usefillo/dom demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.