
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
dialog-component
Advanced tools
Dialog component with structural styling to give you a clean slate.
Live demo is here
$ npm install dialog-component
show
the dialog is shownhide
the dialog is hiddenescape
the dialog was closed via the escape keyclose
the dialog was closed via the close buttonDisplay a dialog with a msg
only.
Display a dialog with title
and msg
.
Make the dialog closable, this adds a × that users make click to forcefully close the dialog.
Assign the effect name, driven by CSS transitions. Out of the box the following are available:
slide
fade
scale
Add a clickable overlay, which closes the dialog.
Add a non-clickable overlay making it modal.
Dialogs are centered by default. If you'd rather use CSS to position the dialog make it fixed
;
no per element CSS properties are added to such dialogs.
This is private as it is implied by other options. If no overlay is used, or the overlay is non-modal then a user may close the dialog by pressing the escape key.
Show the dialog.
Hide the dialog immediately or wait ms
.
Add class name
, useful for styling dialogs differently.
MIT
Install component-test globally in order to run unit tests:
sudo npm install -g component-test2
FAQs
Dialog component
The npm package dialog-component receives a total of 78 weekly downloads. As such, dialog-component popularity was classified as not popular.
We found that dialog-component demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 32 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.