
Research
/Security News
Popular Tinycolor npm Package Compromised in Supply Chain Attack Affecting 40+ Packages
Malicious update to @ctrl/tinycolor on npm is part of a supply-chain attack hitting 40+ packages across maintainers
broccoli-ractive
Advanced tools
This [broccoli](https://github.com/broccolijs/broccoli) plugin compiles Ractive component files. If you're not yet familiar with component files, [start here](https://github.com/ractivejs/component-spec).
This broccoli plugin compiles Ractive component files. If you're not yet familiar with component files, start here.
To try it out:
# Clone this repo and set it up
git clone https://github.com/ractivejs/broccoli-ractive.git
cd broccoli-ractive
npm i
# Fire up broccoli
broccoli serve
Once you're up and running, navigate to localhost:4200. You should see a clock - the one defined in the clock.html component file.
For the demo, we're converting to an AMD module, but you can also generate node.js modules (e.g. for use with the broccoli-browserify plugin) or ES6 modules.
npm i -D broccoli-ractive # `i` is short for `install`, `-D` means `--save-dev`
Inside your brocfile.js
:
var compileRactive = require( 'broccoli-ractive' );
var tree = compileRactive( inputTree, {
destDir: 'path/to/output'
});
The inputTree
option can be a string, e.g. path/to/ractive_components
. The second argument is an object with the following options:
[**/*.html]
(i.e. all HTML files in the input tree). An array of file minimatch patterns to match.amd
. The type of JavaScript module to convert to. Can be either amd
, cjs
(node.js modules) or es6
.## License
MIT.
FAQs
This [broccoli](https://github.com/broccolijs/broccoli) plugin compiles Ractive component files. If you're not yet familiar with component files, [start here](https://github.com/ractivejs/component-spec).
The npm package broccoli-ractive receives a total of 1 weekly downloads. As such, broccoli-ractive popularity was classified as not popular.
We found that broccoli-ractive demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Malicious update to @ctrl/tinycolor on npm is part of a supply-chain attack hitting 40+ packages across maintainers
Security News
pnpm's new minimumReleaseAge setting delays package updates to prevent supply chain attacks, with other tools like Taze and NCU following suit.
Security News
The Rust Security Response WG is warning of phishing emails from rustfoundation.dev targeting crates.io users.