
Research
/Security News
Weaponizing Discord for Command and Control Across npm, PyPI, and RubyGems.org
Socket researchers uncover how threat actors weaponize Discord across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.
icss-utils
Advanced tools
Governs the way tokens are searched & replaced during the linking stage of ICSS loading.
This is broken into its own module in case the behaviour needs to be replicated in other PostCSS plugins (i.e. CSS Modules Values)
import { replaceSymbols, replaceValueSymbols } from "icss-utils";
replaceSymbols(css, replacements);
replaceValueSymbols(string, replacements);
Where:
css
is the PostCSS tree you're working withreplacements
is an JS object of symbol: "replacement"
pairs, where all occurrences of symbol
are replaced with replacement
.A symbol is a string of alphanumeric, -
or _
characters. A replacement can be any string. They are replaced in the following places:
color: my_symbol;
or box-shadow: 0 0 blur spread shadow-color
@media small {}
or @media screen and not-large {}
Extracts and remove (if removeRules is equal true) from PostCSS tree :import
, @icss-import
, :export
and @icss-export
statements.
import postcss from "postcss";
import { extractICSS } from "icss-utils";
const css = postcss.parse(`
:import(colors) {
a: b;
}
:export {
c: d;
}
`);
extractICSS(css);
/*
{
icssImports: {
colors: {
a: 'b'
}
},
icssExports: {
c: 'd'
}
}
*/
By default both the pseudo and at-rule form of the import and export statements
will be removed. Pass the mode
option to limit to only one type.
Converts icss imports and exports definitions to postcss ast
createICSSRules(
{
colors: {
a: "b",
},
},
{
c: "d",
},
// Need pass `rule` and `decl` from postcss
// Please look at `Step 4` https://evilmartians.com/chronicles/postcss-8-plugin-migration
postcss
);
By default it will create pseudo selector rules (:import
and :export
). Pass
at-rule
for mode
to instead generate @icss-import
and @icss-export
, which
may be more resilient to post processing by other tools.
ISC
Glen Maddern, Bogdan Chadkin and Evilebottnawi 2015-present.
[5.1.0] - 2020-11-19
import
/export
This package is a PostCSS plugin that helps you use CSS modules. It allows you to scope CSS by automatically renaming classes and other selectors. It is similar to icss-utils in that it deals with CSS modules, but it is a full plugin rather than a set of utilities.
css-loader is a loader for webpack that interprets `@import` and `url()` like `import/require()` and will resolve them. It also has features for handling CSS modules, which makes it similar to icss-utils. However, css-loader is more integrated with webpack's build system.
This package is a PostCSS plugin that enables namespacing of CSS selectors according to the ICSS specification. It is similar to icss-utils in that it works with ICSS, but it focuses more on transforming selectors for scoping purposes.
FAQs
ICSS utils for postcss ast
The npm package icss-utils receives a total of 15,877,297 weekly downloads. As such, icss-utils popularity was classified as popular.
We found that icss-utils demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Socket researchers uncover how threat actors weaponize Discord across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.
Security News
Socket now integrates with Bun 1.3’s Security Scanner API to block risky packages at install time and enforce your organization’s policies in local dev and CI.
Research
The Socket Threat Research Team is tracking weekly intrusions into the npm registry that follow a repeatable adversarial playbook used by North Korean state-sponsored actors.