Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Low-level CSS toolkit – the original Functional CSS library http://basscss.com
Basscss is a lightweight collection of immutable utilities designed for speed, clarity, performance, and scalability.
Basscss v8 is the final version of Basscss, which means no major, breaking changes will be introduced. Minor features and patches may be added, but due to the nature of this CSS approach, there are virtually no bugs in Basscss.
Using clear, humanized naming conventions, Basscss is quick to internalize and easy to reason about while speeding up development time with more scalable, more readable code.
Things behave exactly as expected with immutable utilities and styles that follow the open/closed principle to help prevent common pitfalls with CSS.
Reusable, interoperable styles work like building blocks to lay the foundation for any stylesheet and can be mixed and matched in any number of combinations.
Basscss strikes a balance between consistency and flexibility to allow for rapid prototyping and quick iterative changes when designing in the browser.
Basscss provides lightweight, performant styles and flexible utilities to design for any device and to help reduce boilerplate in stylesheets.
Modular and customizable typography and layout styles don’t dictate what things should look like and play well with other stylesheets and frameworks.
The core Basscss package does not include any base element styles. For an out-of-the-box solution, see:
https://github.com/basscss/basic
In addition to the core modules, optional modules, including responsive margin, padding, layout, and typography styles, can be found here:
https://github.com/basscss/addons
For a bundle with the core Basscss and all optional modules, see:
https://github.com/basscss/ace
See CONTRIBUTING.md
This library was largely inspired and influenced by the following people
FAQs
Low-level CSS toolkit
We found that basscss demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.