
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
Buefy is a lightweight library of responsive UI components for Vue.js based on Bulma framework and design.
Because not all of Vue 2 features could be reproduced with Vue 3, there are some breaking changes. Please refer to CHANGELOG.md for more details. The biggest breaking change is obviously, buefy does not work with Vue 2.
npm install buefy
The documentation is in the docs directory, it serves as the demo as well.
Browse online documentation here.
You need Vue.js version 3.0+. (Vue 2 is not supported)
npm install buefy
Bundle
import { createApp } from "vue";
import Buefy from "buefy";
import "buefy/dist/css/buefy.css";
const app = createApp();
app.use(Buefy);
or Individual Components
import { createApp } from "vue";
import { Field, Input } from "buefy";
import "buefy/dist/css/buefy.css";
const app = createApp();
app.use(Field);
app.use(Input);
<link
rel="stylesheet"
href="https://cdn.jsdelivr.net/npm/@mdi/font@5.8.55/css/materialdesignicons.min.css"
/>
If you want to customize the icons or the theme, refer to the customization section on the documentation.
<!-- Buefy CSS -->
<link rel="stylesheet" href="https://unpkg.com/buefy/dist/buefy.min.css" />
<!-- Buefy JavaScript -->
<script src="https://unpkg.com/buefy/dist/buefy.min.js"></script>
Currently, including buefy
via <script>
is not working.
Please see the issue #221.
As a temporary workaround, add the following snippet before initializing Buefy:
<script>
// we need this tweak because Buefy is not built for browsers
window.process = { env: { NODE_ENV: 'production' } };
</script>
To incorporate the latest changes from the development branch of buefy-next, you can install developer releases from the GitHub npm registry. However, proceed with caution as these packages may be deleted or retracted without notice.
Steps:
Generate a Personal Access Token:
Create a personal access token on GitHub with read access to the GitHub Packages registry.
Configure npm:
In your terminal, execute the following commands:
npm login --auth-type=legacy --registry=https://npm.pkg.github.com
USERNAME: <their GitHub username>
PASSWORD: <personal access token issued at Step 1>
echo "@buefy:registry=https://npm.pkg.github.com" > .npmrc
Select a Developer Release:
Visit the Buefy package registry: https://github.com/buefy/buefy/pkgs/npm/buefy on GitHub.
Choose any developer release that suits your needs.
Package Naming Conventions:
Buefy developer releases follow a specific naming format:
@buefy/buefy@<package version>-<dev commit hash>
<package version>
: This represents the intended stable release version that the developer release will eventually be included in.
<dev commit hash>
: This part indicates that it's a developer release and includes a unique commit hash that identifies the specific code changes in that release.
Due to the GitHub npm registry's requirements, the package name must be scoped; i.e., prefixed with @buefy/
.
Install the Package:
Copy the provided command from GitHub, which will resemble this:
npm install buefy@npm:@buefy/buefy@<package version>-<dev commit hash>
Alternatively, to fetch the latest release from the developer release registry, run:
npm install buefy@npm:@buefy/buefy@latest
However, note it is not recommended to use the latest version of our developer release, as its stability fluctuates.
Congratulations! You've successfully installed a Buefy developer release.
For further details on the GitHub npm registry refer to the official GitHub documentation
https://github.com/buefy/buefy
Recent versions of Firefox, Chrome, Edge, Opera and Safari. IE10+ is only partially supported.
Please see the contributing guidelines
Version will follow v0.Y.Z, where:
Kikuo Emoto | Wesley Ford |
Special thanks to Rafael Beraldo, the original author, and Walter Tommasi, a former core maintainter of Buefy.
Thanks goes to these wonderful people (emoji key):
Rafael Beraldo 💻 | Alexandre Paradis 💻 | Yuxing Liao 💻 | Adrien 💻 | Apolokak Lab 💻 | Antério Vieira 💻 | Jorge Nieto 💻 | Mateus Machado Luna 💻 |
All contributors |
This project follows the all-contributors specification. Contributions of any kind welcome!
Code released under MIT license.
FAQs
Lightweight UI components for Vue.js (v3) based on Bulma
The npm package buefy receives a total of 27,977 weekly downloads. As such, buefy popularity was classified as popular.
We found that buefy demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.