
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
lazy-upload
Advanced tools
lazy-upload is a library which aims to simplify the file upload flow
Using npm:
npm i --save lazy-upload
Using yarn:
yarn add --dev lazy-upload
Here are examples of how you can use lazy-upload
.
File upload hook
const UPLOAD_FILES_URL = '';
export const UploadField = () => {
const {
acceptedFiles,
attributes,
rejectedFiles,
reset,
upload,
uploadedFiles,
} = useLazyUpload({});
console.log({ rejectedFiles, uploadedFiles });
return (
<form
onSubmit={e => {
upload({
config: {
url: UPLOAD_FILES_URL,
method: 'POST',
},
fileList: acceptedFiles,
});
e.preventDefault();
}}
>
<label htmlFor="file-upload">Choose files:</label>
<input {...attributes} id="file-upload" name="file-upload" />
<button onClick={reset}>Reset</button>
<button type="submit">Submit</button>
</form>
);
};
Tests are written with jest
Using jest:
yarn run test
Deployment is done with Travis.
Please read CONTRIBUTING.md for details on our code of conduct, and the process for submitting pull requests to us.
We use SemVer for versioning. For the versions available, see the tags on this repository.
See also the list of contributors who participated in this project.
Give a ⭐️ if this project helped you!
This project is licensed under the MIT License - see the LICENSE file for details
FAQs
Simplify the file upload flow
The npm package lazy-upload receives a total of 3 weekly downloads. As such, lazy-upload popularity was classified as not popular.
We found that lazy-upload demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.