
Research
/Security News
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.
@webreflection/signal
Advanced tools
Social Media Photo by Louis Reed on Unsplash
A minimalistic signals implementation, derived from the post Signals: the nitty-gritty, which size, once minified and brotlied, is 528 bytes.
dispose() is invokedbatch operation is updating all inner signals at onceFor anything more complex please check usignal out.
signal(value) to create a new signal with a reactive .valuecomputed(fn[, initialValue]) to create a computed signal with a read-only .valueeffect(fn) to create an effect and return a dispose functionbatch(fn) to update multiple signals at once and invoke related effects onceuntracked(fn) to make a callback that can read some signals without subscription to themSignal to compare via instanceof Signal instancesComputed to compare via instanceof Computed instancesComputed accepts an initial value to pass to the callback. The callback will keep receiving the previous value on each new invoke.
// import {signal, effect} from 'https://unpkg.com/@webreflection/signal';
// const {signal, effect} = require('@webreflection/signal');
import {signal, effect} from '@webreflection/signal';
const single = signal(1);
const double = signal(10);
const triple = signal(100);
const dispose1 = effect(() => {
console.log(`
#1 effect
single: ${single}
double: ${double}
`);
});
const dispose2 = effect(() => {
console.log(`
#2 effect
double: ${double}
triple: ${triple}
`);
});
++double.value;
// logs single 1, double 11
// logs double 11, triple 100
dispose2();
++double.value;
// logs single 1, double 11
FAQs
A minimalistic signals implementation
We found that @webreflection/signal demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.

Research
/Security News
Docker and Socket have uncovered malicious Checkmarx KICS images and suspicious code extension releases in a broader supply chain compromise.

Product
Stay on top of alert changes with filtered subscriptions, batched summaries, and notification routing built for triage.