Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
neverendingqs-material-sidenav
Advanced tools
[![npm version](https://badge.fury.io/js/neverendingqs-material-sidenav.svg)](https://badge.fury.io/js/neverendingqs-material-sidenav)
A fork from https://github.com/SuphanutJui/Material-Sidenav-Ghost-Theme.
A Ghost blogging-platform theme, based on Materialize 0.97.6
For the demo please visit my own blog: https://www.suphanutjui.com
Here's what you have to edit:
I have copied just some of the codes from FontAwesome and Animate.css which are neccesary for rendering webpage, so if you want to use another animations or icons, you have to include the stylesheets back into default.hbs.
Also, this theme have been made for Thai language, so font size might not be optimized for English. Please feel free to edit this theme.
This theme is based on Materialize framework, animation from animate.css and my own code so it's not light-weighted theme. Also, animation doesn't seem to work smoothly but when I have time and passion, it will be fixed. :D
Download (or clone) the respository, put it in ghost/content/themes.
Then restart your Ghost and select "Material Sidenav" in your "General" page of the settings.
There will be 2 versions of stylesheet for you; minified and unminified stylesheet. So, you have to edit unminified version and minify it respectively. Or, if you prefer to edit minified version, it's probably fine. :)
####Fonts & Icons
###License
MIT License
FAQs
[![npm version](https://badge.fury.io/js/neverendingqs-material-sidenav.svg)](https://badge.fury.io/js/neverendingqs-material-sidenav)
The npm package neverendingqs-material-sidenav receives a total of 1 weekly downloads. As such, neverendingqs-material-sidenav popularity was classified as not popular.
We found that neverendingqs-material-sidenav demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.