
Security News
Google’s OSV Fix Just Added 500+ New Advisories — All Thanks to One Small Policy Change
A data handling bug in OSV.dev caused disputed CVEs to disappear from vulnerability feeds until a recent fix restored over 500 advisories.
postcss-simple-vars
Advanced tools
PostCSS plugin for Sass-like variables.
You can use variables inside values, selectors and at-rule parameters.
$dir: top;
$blue: #056ef0;
$column: 200px;
.menu_link {
background: $blue;
width: $column;
}
.menu {
width: calc(4 * $column);
margin-$(dir): 10px;
}
.menu_link {
background: #056ef0;
width: 200px;
}
.menu {
width: calc(4 * 200px);
margin-top: 10px;
}
If you want be closer to W3C spec, you should use postcss-custom-properties and postcss-at-rules-variables plugins.
Look at postcss-map for big complicated configs.
Read full docs on GitHub.
7.0.1
The postcss-css-variables package allows you to use native CSS custom properties (variables) in a way that is compatible with older browsers. Unlike postcss-simple-vars, it focuses on providing a polyfill for native CSS variables rather than introducing a new syntax.
The postcss-advanced-variables package extends the functionality of postcss-simple-vars by adding support for conditionals, loops, and more complex variable manipulations. It is more feature-rich but also more complex to use.
The postcss-mixins package allows you to create reusable chunks of CSS, similar to Sass mixins. While it doesn't focus solely on variables, it complements postcss-simple-vars by providing additional tools for code reuse and modularity.
FAQs
PostCSS plugin for Sass-like variables
The npm package postcss-simple-vars receives a total of 471,862 weekly downloads. As such, postcss-simple-vars popularity was classified as popular.
We found that postcss-simple-vars demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
A data handling bug in OSV.dev caused disputed CVEs to disappear from vulnerability feeds until a recent fix restored over 500 advisories.
Research
/Security News
175 malicious npm packages (26k+ downloads) used unpkg CDN to host redirect scripts for a credential-phishing campaign targeting 135+ organizations worldwide.
Security News
Python 3.14 adds template strings, deferred annotations, and subinterpreters, plus free-threaded mode, an experimental JIT, and Sigstore verification.