
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
@yoast/components
Advanced tools
We have not released changes in this package since May 18, 2021. And are not planning to do so in the future.
We are not actively maintaining this package for a while now and are using the @yoast/ui-library package in our newer projects.
The package will remain available in its current state on NPM, but will be marked as deprecated.
The package will remain available in this repo on GitHub, until we ourselves are no longer using it.
The Yoast/Components package is not pre-build. So if you would like to include @yoast/components into your project we will need a few steps to set it up.
Install the package by running yarn add @yoast/components.
Include Yoast/components into the babel-loader of your webpack.config. This will look something like this: include: [ paths.appSrc, /node_modules[/\\](@yoast)[/\\].*/ ]
It can be that you will need presets for the babel-loader. These are: presets: [ "@babel/preset-env", "@babel/preset-react" ]
Note that you will also need to install these presets. Run yarn add --dev @babel/preset-env @babel/preset-react
Because we are importing CSS in our JavaScript, your JavaScript bundler needs to be able to interpret CSS.
Therefore, you will need to use a css-loader in your bundler in order to use this package.
E.g. in Webpack: https://webpack.js.org/loaders/css-loader/
Make sure to add the CSS imports to your project. import "@yoast/components/base"; This is a collection of all the CSS in @yoast/components.
It should be imported in App.js or index.js of your react project.
The MultiSelect component requires the presence of both jQuery and Select2. Make sure that they are available on the global window object before the component is instantiated.
If you are working in a WordPress environment, WordPress will automatically load jQuery for you so you only need to worry about Select2.
FAQs
Yoast Components
The npm package @yoast/components receives a total of 61 weekly downloads. As such, @yoast/components popularity was classified as not popular.
We found that @yoast/components demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 8 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.