
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
A simple CSS foundation with responsive typography and input styling, built with PostCSS.
View the documentation.
In the age of Flexbox, CSS grid, and other exciting layout features, there is less and less need for a bloated CSS framework. What we do need is a simple foundation on top of which to build our own styles. Enter HiQ.
Start using HiQ by using npm to install the package or use the Github repository to get the latest development version.
npm install hiq
Import the compiled minified version in your CSS:
@import '~hiq/dist/hiq.min.css';
Import the source version and process your CSS using PostCSS. This will give you access to the utility mixins that HiQ provides. Note that source files use the .css file extension.
@import '~hiq/css/hiq.css';
To take full advantage of the PostCSS features in HiQ, you will need to configure your postcss.config.js to include these plugins (already installed with HiQ):
module.exports = {
plugins: [
require('postcss-mixins'),
require('postcss-custom-selectors'),
require('postcss-custom-media')
]
};
For more information on using PostCSS, read the PostCSS documentation usage section.
HiQ is built with custom properties and is easy to theme according to your own brand. Refer to the custom property reference, grab the properties you want to change, and include them in your project.
These can be included anywhere, before or after HiQ!
@import '~hiq/dist/hiq.min.css';
:root {
--hiq-button-border-color: lightgray;
--hiq-button-background-color: lightgray;
--hiq-button-text-color: black;
}
If you want your custom property definitions to apply globally, you should define them on the root element using :root. Otherwise, you can scope them to whatever element you wish.
For example, if you are creating a button variant, you could define the locally scoped custom properties on a specific class:
button.is-primary {
--button-border-color: blue;
--button-background-color: blue;
--button-text-color: white;
}
FAQs
A lightweight, progressive, high-IQ PostCSS framework.
We found that hiq demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.