
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
Just UI components library and components toolkit.
To see my-app example:
npm install
npm run my-app
Then open examples/my-app/index.html in browser (Google Chrome recommended).
Component props is an key-value object.
Component constructor receive one parameter props.
mountElIt is an root element where component is mounted. This element do not changes by component. It used just for render component inside.
This process contains tree steps: 1. clean content from the mountEl, 2. insert new component content,
3. collect refs.
You can re-define render() method at child class of Component and put all element-specific logic
(add event listeners etc.) there. Note: you should call super.render().
refsYou can give to each element attribute data-ref="<refName>". Then after render you can access this.refs.<refName>
to get access to elements. It's very useful when you override render() method and wants get quick
access to specific element.
Note: if you give data-ref to two or more elements - you will get array of elements in this.refs.<refName>.
FAQs
Just UI components library and components toolkit.
We found that j-ui demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.