Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
ember-cli-sassdash
Advanced tools
An Ember CLI addon for adding Sassdash to Ember.js applications.
Ember CLI Sassdash is an addon for adding Sassdash to Ember applications.
Developed with Sass toolkit developer in mind, Sassdash gives you nearly the full expressive power of lodash for JavaScript, inside your SCSS projects. Sassdash is a collection of utility functions, just like lodash. Sassdash never outputs any CSS declarations as it provides no mixins to do so. Read more.
ember install ember-cli-sassdash
This addon will automatically install ember-cli-sass as a dependency and create an app.scss
file in your application at styles/app.scss
with the following import statement at the top of the file:
@import "sassdash";
Both the previously mentioned @import
as well as the ember-cli-sass
addon are required.
This step is handled in the default blueprint, but make sure in your app.scss
to simply add the following at the top of the file (if it isn't already included):
@import "sassdash";
Discover the power of Sassdash over at the official documentation.
Check out the dummy app. It showcases some cool examples of Sassdash in action.
git clone https://github.com/willviles/ember-cli-sassdash.git
cd ember-cli-sassdash
npm install
ember serve
FAQs
An Ember CLI addon for adding Sassdash to Ember.js applications.
The npm package ember-cli-sassdash receives a total of 1 weekly downloads. As such, ember-cli-sassdash popularity was classified as not popular.
We found that ember-cli-sassdash demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.