
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
granite-editor
Advanced tools
Create vibrant, full custom pages in the browser by dragging, dropping, and resizing a variety of plugins on the page.
Create vibrant, full custom pages in the browser by dragging, dropping, and resizing a variety of plugins on the page.
Powered by React and Redux.
It is recommended that you use
npm link on this directory and then create another project with react-scripts which
requires this project by running npm link granite-editor in your new react-scripts project root. Add the editor
via an import Editor from 'granite-editor' and use it as normal.Then running
Update: You can run npm run build --watch or yarn run build --watch will continually recompile your changes and
react-scripts will pick up and rebuild.yarn run dev to start up a development instance of the editor. The above instructions may work for
developing this project inside another project, but are no longer recommended.
Editor Constraints/Rules:
This project exists on npm at granite-editor.
The workflow for pushing new releases is as follows:
git tag to tag your new version, using the format v0.0.0package.json.yarn run build to output a fresh build artifact.git push --tagsnpm publishFAQs
Create vibrant, full custom pages in the browser by dragging, dropping, and resizing a variety of plugins on the page.
We found that granite-editor demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.