Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
A Vue 3 Component Library. Fairly Complete, Theme Customizable, Uses TypeScript, Fast
A Vue 3 Component Library
Fairly Complete, Theme Customizable, Uses TypeScript, Fast
Kinda Interesting
English | 中文
DingTalk Group 1 (Member limit reached) 33482509
DingTalk Group 2 (Member limit reached) 35886835
DingTalk Group 3 (Member limit reached) 32377370
DingTalk Group 4 (Member limit reached) 8165002788
DingTalk Group 5 (Member limit reached) 31205022250
DingTalk Group 6 62720001971
There are more than 90 components. Hope they can help you write less code.
What's more, they are all treeshakable.
We provide an advanced type safe theme system built using TypeScript. All you need is to provide a theme overrides object in JS. Then all the stuff will be done by us.
What's more, no less/sass/css variables, no webpack loaders are required.
All the stuff in Naive UI is written in TypeScript. It can work with your typescript project seamlessly.
What's more, you don't need to import any CSS to use the components.
I try to make it not rather slow. At least select, tree, transfer, table and cascader work with virtual list.
What's more, ..., no more. Just enjoy it.
Use npm to install.
npm i -D naive-ui
npm i -D vfonts
Naive UI recommends using xicons as icon library.
Please see CONTRIBUTING.md.
Naive UI is licensed under the MIT license.
Graphics resources of result
component is licensed under the CC-BY 4.0. The graphics resources come from Twemoji.
FAQs
A Vue 3 Component Library. Fairly Complete, Theme Customizable, Uses TypeScript, Fast
The npm package naive-ui receives a total of 26,959 weekly downloads. As such, naive-ui popularity was classified as popular.
We found that naive-ui demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.