
Research
/Security News
DuckDB npm Account Compromised in Continuing Supply Chain Attack
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
css-customs-loader
Advanced tools
Exposes custom properties, custom media queries and custom selectors to JavaScript
A webpack loader that exposes CSS customs to JavaScript.
yarn add css-customs-loader postcss-loader postcss-preset-env
You need to add css-customs-loader before css-loader:
// webpack.config.js
module.exports = {
// ...
module: {
rules: [
{
test: /\.css$/,
use: [
'style-loader',
{
loader: 'css-customs-loader'
// defaults
options: {
onlyLocals: false,
},
},
'css-loader?importLoaders=1',
'postcss-loader',
],
},
],
},
}
css-customs-loader detects any valid PostCSS configuration (including options passed to postcss-loader!), so let's create one. importFrom
will point to a global.css
file containing our customs and, for the sake of this example, we'll enable all features related to CSS customs:
// postcss.config.js
module.exports = {
plugins: {
'postcss-preset-env': {
importFrom: 'src/global.css',
features: {
'custom-properties': true, // already enabled by default
'custom-media-queries': true,
'custom-selectors': true,
},
},
},
}
onlyLocals
This option should be enabled in situations like pre-rendering. You should combine it with onlyLocals
option in css-loader v2 or css-loader/locals
loader in css-loader v1. (Don't use style-loader when pre-rendering.)
See usage instructions in the main readme.
FAQs
Exposes custom properties, custom media queries and custom selectors to JavaScript
We found that css-customs-loader demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
Security News
The MCP Steering Committee has launched the official MCP Registry in preview, a central hub for discovering and publishing MCP servers.
Product
Socket’s new Pull Request Stories give security teams clear visibility into dependency risks and outcomes across scanned pull requests.