
Security News
PodRocket Podcast: Inside the Recent npm Supply Chain Attacks
Socket CEO Feross Aboukhadijeh discusses the recent npm supply chain attacks on PodRocket, covering novel attack vectors and how developers can protect themselves.
@zywave/zui-base-styles
Advanced tools
npm:
> npm i --save @zywave/zui-base-styles
yarn:
> yarn add @zywave/zui-base-styles
See the documentation site for more information.
Be sure all dependencies for the monorepo have been installed (instructions at the root CONTRIBUTING.md)
Watch
> npx gulp watch
Run
> npx gulp run
Within base.scss
and normalize.scss
you'll notice duplication of selectors specifying base styles, these selectors are chained with a class of .zui
.
h1,
h1.zui {
font-size: rem(26);
}
.zui
is currently experimental and is available as a prototype package via zui-app-styles
in the exp
branch. This will soon be available in the dev
branch after testing. .zui
was created to allow for simpler class names within our style library, and to avoid clashing styles; i.e. if a user pulls in a 3rd party stylesheet which defines .row
, but ZUI also defines .row
these classes could mix but .zui
instead removes all styles on itself first, and then adds the ZUI defined styles.
Why is .zui
in zui-base-styles
? zui-base-styles
and zui-app-styles
are not dependencies of each other, they could be used independently. Since .zui
removes all styles from an element it resides on, we wanted to preserve the styles zui-base-styles
provides, hence the need to add the second set of selectors chained with .zui
.
FAQs
## Installation
The npm package @zywave/zui-base-styles receives a total of 323 weekly downloads. As such, @zywave/zui-base-styles popularity was classified as not popular.
We found that @zywave/zui-base-styles demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Socket CEO Feross Aboukhadijeh discusses the recent npm supply chain attacks on PodRocket, covering novel attack vectors and how developers can protect themselves.
Security News
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
Product
Socket Firewall is a free tool that blocks malicious packages at install time, giving developers proactive protection against rising supply chain attacks.