🚨 Shai-Hulud Strikes Again:More than 500 packages and 700+ versions compromised.Technical Analysis
Socket
Book a DemoInstallSign in
Socket

@wemnyelezxnpm/voluptatibus-animi-error

Package Overview
Dependencies
Maintainers
1
Versions
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@wemnyelezxnpm/voluptatibus-animi-error

![uikit wordmark](https://raw.githubusercontent.com/wemnyelezxnpm/voluptatibus-animi-error/main/wordmark.svg)

latest
Source
npmnpm
Version
1.0.0
Version published
Maintainers
1
Created
Source

uikit wordmark

UIKit

Build and Test results Top language Commits per month

UI toolkit monorepo containing a React component library, UI utilities, a generative AI LLM parser, an AWS AppSync fetch utility, and more

Packages

NPM Package NameVersionDescription
@acusti/appsync-fetchlatest versionA promise-based node.js function for making AWS AppSync API graphql requests
@acusti/aws-signature-v4latest versionAn isomorphic module implementing the AWS Signature V4 (SigV4) signing process for requests
@acusti/css-valueslatest versionUtilities for parsing different types of CSS values
@acusti/css-value-inputlatest versionReact component that renders a CSS value input
@acusti/date-pickerlatest versionReact component that renders a date picker with range support
@acusti/dropdownlatest versionReact component that renders a dropdown UI element
@acusti/input-textlatest versionReact component that renders an uncontrolled text input
@acusti/matchmakinglatest versionUtilities for approximate string matching (i.e. fuzzy search)
@acusti/parsinglatest versionLoosely parse a string as JSON with numerous affordances for syntax errors
@acusti/postlatest versionA promise-based node.js function for making graphql requests
@wemnyelezxnpm/voluptatibus-animi-errorlatest versionReact component that renders a CSS string to the <head>
@acusti/textuallatest versionUtilities for transforming and formatting text
@acusti/uniquifylatest versionA function that ensures a string is unique amongst items
@acusti/use-bounding-client-rectlatest versionReact hook for getting an element’s boundingClientRect
@acusti/use-is-out-of-boundslatest versionReact hook to check if an element overlaps its bounds
@acusti/use-keyboard-eventslatest versionReact hook for adding key event listeners to your UI
@acusti/webcryptolatest versionIsomorphic method for accessing the webcrypto API

The React components are documented and illustrated in the storybook instance, which is located at packages/docs/ in the repository.

Tests

The monorepo uses vitest to run its tests. To run tests across all packages, use yarn test. To run them in watch mode, use yarn test:watch.

Building and Publishing

To build all packages, run yarn build. This will trigger tsc --build and yarn flowgen for all packages.

To build the storybook docs, run yarn build:stories, which will run yarn build and then the default storybook build command.

To publish all packages, manually update each packages’s version field in their package.json. If any of the packages depends on any of the other packages being updated, be sure to update the dependency version as well. Then run yarn publish. Publishing will trigger a build before running npm publish to ensure that the latest changes are published. To publish only a single package, use yarn workspace <package-name> npm publish --access public (e.g. yarn workspace @acusti/css-value-input npm publish --access public), but note that in that case, you are responsible for running yarn build yourself before triggering the publish.

After publishing the packages, run yarn to update the yarn.lock file and then commit the version updates with a message in the form of: :arrow_up: Bump package versions to _._._.

Developing

The two main run scripts for developing are yarn dev:watch, which kicks off the TypeScript compiler in --watch mode, and yarn dev:stories, which kicks off the default storybook command from packages/docs/. To run both of those in a single terminal window, use yarn dev.

Keywords

write

FAQs

Package last updated on 25 Apr 2024

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts