
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
@virtuoso.dev/reactive-engine-react
Advanced tools
@virtuoso.dev/reactive-engine-react provides React bindings for @virtuoso.dev/reactive-engine-core: an EngineProvider component and hooks for reading cell values and publishing into nodes from components.
npm install @virtuoso.dev/reactive-engine-core @virtuoso.dev/reactive-engine-react
import { Cell } from '@virtuoso.dev/reactive-engine-core'
import { EngineProvider, useCellValue, usePublisher } from '@virtuoso.dev/reactive-engine-react'
const count$ = Cell(0)
function Counter() {
const count = useCellValue(count$)
const setCount = usePublisher(count$)
return <button onClick={() => setCount(count + 1)}>{count}</button>
}
export function App() {
return (
<EngineProvider>
<Counter />
</EngineProvider>
)
}
useCellValue / useCellValues - subscribe to one or several cellsuseCell - read a cell value and get a publisher for itusePublisher - get a publisher function for a nodeuseEngineDiagnostics - observe propagation cycles from the nearest engineuseEngine / useEngineRef - access the engine instance from contextuseRemoteCell, useRemoteCellValue, useRemoteCellValues, useRemotePublisher, useRemoteEngineDiagnostics - work with another engine instanceUse the provider configuration when initialization publications must be included:
<EngineProvider
diagnostics={{
observer: (cycle) => sendToTelemetry(cycle),
options: { captureValues: 'summary', redact },
}}
>
<App />
</EngineProvider>
Use useEngineDiagnostics(observer, options) inside a provider, or useRemoteEngineDiagnostics(engineSource, observer, options) from a sibling or external tool. Hook subscriptions start after commit. They do not observe initFn publications.
Diagnostics do not retain cycles or update React state. Store records explicitly in a bounded external store if a diagnostic interface needs history.
MIT
FAQs
React bindings for the Virtuoso reactive engine.
We found that @virtuoso.dev/reactive-engine-react demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.