
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
react-circle
Advanced tools
Renders a svg circle + percentage. It just works
https://zzarcon.github.io/react-circle
$ yarn add react-circle
Basic 🙃
ReactCircle is opinionated and comes with default size and colors, just pass the progress prop to get them:
import Circle from 'react-circle';
<Circle
progress={35}
/>
Custom 💅
Optionally, you can pass the following props and customize it as your will
import Circle from 'react-circle';
// All avaliable props for customization:
// Details are ordered as:
// <Type>: <Description>
<Circle
animate={true} // Boolean: Animated/Static progress
animationDuration="1s" //String: Length of animation
responsive={true} // Boolean: Make SVG adapt to parent size
size={150} // Number: Defines the size of the circle.
lineWidth={14} // Number: Defines the thickness of the circle's stroke.
progress={69} // Number: Update to change the progress and percentage.
progressColor="cornflowerblue" // String: Color of "progress" portion of circle.
bgColor="whitesmoke" // String: Color of "empty" portion of circle.
textColor="hotpink" // String: Color of percentage text color.
textStyle={{
font: 'bold 5rem Helvetica, Arial, sans-serif' // CSSProperties: Custom styling for percentage.
}}
percentSpacing={10} // Number: Adjust spacing of "%" symbol and number.
roundedStroke={true} // Boolean: Rounded/Flat line ends
showPercentage={true} // Boolean: Show/hide percentage.
showPercentageSymbol={true} // Boolean: Show/hide only the "%" symbol.
/>
FAQs
Unknown package
We found that react-circle demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.