
Security News
Nx npm Packages Compromised in Supply Chain Attack Weaponizing AI CLI Tools
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.
github-repository
Advanced tools
Polyfill tags if you need them. This will include ShadowDOM and Custom Elements support.
<script src="https://unpkg.com/@webcomponents/webcomponentsjs@latest/bundles/webcomponents-sd-ce.js"></script>
Loading this component. It would be a good idea to use a specific version instead of latest
.
<script src="https://unpkg.com/github-repository@latest/dist/github-repository.min.js"></script>
Set the owner-repo
attribute to the username/repository
of a GitHub repository.
<github-repository owner-repo="angular/angular"></github-repository>
For more advanced usage you can include:
<img slot="images" />
to include a preview image<a slot="badges"><img /></a>
to include status badges<github-repository owner-repo="abraham/twitter-status">
<img slot="images" src="https://raw.githubusercontent.com/abraham/twitter-status/master/images/simple.png" alt="Twitter Status embed preview" />
<a slot="badges" href="https://npmjs.com/package/twitter-status" target="_blank">
<img src="https://img.shields.io/npm/v/twitter-status.svg?style=flat&label=version&colorB=4bc524" alt="Version Status" />
</a>
<a slot="badges" href="https://circleci.com/gh/abraham/twitter-status" target="_blank">
<img src="https://img.shields.io/circleci/project/github/abraham/twitter-status.svg?style=flat&label=macos" alt="macOS Build Status" />
</a>
<a slot="badges" href="https://travis-ci.org/abraham/twitter-status" target="_blank">
<img src="https://img.shields.io/travis/abraham/twitter-status.svg?style=flat&label=linux" alt="Linux Build Status" />
</a>
<a slot="badges" href="https://ci.appveyor.com/project/abraham/twitter-status" target="_blank">
<img src="https://img.shields.io/appveyor/ci/abraham/twitter-status.svg?style=flat&label=windows" alt="Windows Build Status" />
</a>
</github-repository>
This Web Component makes unauthenticated requests to the GitHub API. Since the GitHub API has a fairly restrictive 60 requests/hour per IP address, API responses are cached in localStorage
.
GithubRepository is released under an MIT license.
Built, tested, and published with Nutmeg.
FAQs
GitHub Repository Web Component
The npm package github-repository receives a total of 80 weekly downloads. As such, github-repository popularity was classified as not popular.
We found that github-repository demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.
Security News
CISA’s 2025 draft SBOM guidance adds new fields like hashes, licenses, and tool metadata to make software inventories more actionable.
Security News
A clarification on our recent research investigating 60 malicious Ruby gems.