
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@warmio/uiPortable React components shared by Warm products. Install this package with the exact
@warmio/design@1.0.0 CSS contract, import @warmio/design/globals.css once, and add the package's
compiled files to Tailwind's source detection:
Independently deployed Warm products cannot import runtime code from the private warm-app
workspace, so libraries/public-ui/ must be a standalone public package rather than another private
workspace entry point. tools/tasks/check-ui-package.mjs is a dedicated package-boundary check
because the existing application checks do not build, pack, and inspect a public npm tarball.
.github/workflows/publish-ui.yml is separate from application deployment workflows so npm trusted
publishing can bind credentials to one reviewable package-release boundary without granting an app
deployment permission to publish packages.
@import '@warmio/design/globals.css';
@source '../node_modules/@warmio/ui/dist';
The 1.1.0 public surface contains the Warm badge, logo, Button, Text and StackedDisplay,
DropdownMenu, Sheet, and complete responsive Sidebar family including SidebarBrand and
SidebarAccountTrigger. Styling is sealed: use documented semantic presentations and layout
wrappers, never className or style overrides. DropdownMenu interaction feedback requires the
exact public peer cuelume@0.1.0.
The published artifact is standalone and never imports private warm-app workspace packages.
FAQs
Portable, sealed React components for Warm products.
The npm package @warmio/ui receives a total of 141 weekly downloads. As such, @warmio/ui popularity was classified as not popular.
We found that @warmio/ui demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.