data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
aria-live-storybook-addon
Advanced tools
Observe and log aria-live region changes in the addon panel
Debugging ARIA live regions is cumbersome. Validating that live regions are connected should be easy, automatic, and available right in the story.
First, install the addon.
$ yarn add aria-live-storybook-addon
Add this line to your main.js file (create this file inside your Storybook config directory if needed).
module.exports = {
addons: ['aria-live-storybook-addon'],
};
Once installed, you'll have a new Panel: Aria Live Regions
.
This panel will observe changes to aria-live=polite
and aria-live=assertive
elements in your story.
Implementation examples can be found in Storybook on Chromatic.
This addon only acklowedges the first aria-live
element of types polite
and assertive
in a story.
In practice, an application should only have one aria-live
announcer per type.
When using UI libraries like React, browsers like Chrome and Firefox might not observe text changes, only additions. This is true of this addon as well as the screen reader experience.
To ensure that users of assistive technologies are able to observe changes, be sure to clear the content of aria-live
elements.
If you are looking for implementation strategies, consider this implementation using React Hooks.
FAQs
Observe and log aria-live region changes in the addon panel
The npm package aria-live-storybook-addon receives a total of 26 weekly downloads. As such, aria-live-storybook-addon popularity was classified as not popular.
We found that aria-live-storybook-addon demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.