Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
react-fela
Advanced tools
Official React bindings for Fela.
This package only includes React bindings for Fela.
It assumes you already know about Fela and how to use it.
yarn add react-fela
You may alternatively use npm i --save react-fela
.
For more information and best practices on how to effectively use this package, please check out the main Fela Documention - Usage with React. You will find some useful examples and a basic introduction on how to use Fela with React.
Checkout the API Reference - Bindings for further technical information on how the React/Preact/Inferno bindings work.
Fela is licensed under the MIT License.
Documentation is licensed under Creative Common License.
Created with ♥ by @robinweser and all the great contributors.
11.0.0
| Package | Changes |
| --- | --- |
| fela<br>fela-dom | (#750) Added the sortMediaQuery
config option for more flexible and dynamic media query sorting. It is backwards compatible and respects mediaQueryOrder
, but we decided to do a major release nevertheless. |
| fela-plugin-responsive-value | (#748) Introducing a plugin to resolve responsive media query values. |
| fela-plugin-named-keys | (#749) The plugin now merges resolve key values with existing key values. |
| fela-dom | (#741) Fixed a bug where in devMode @supports
rules weren't rendered correctly.<br />Fixed a big where static styles, keyframes and fonts were rendered twice. |
FAQs
React bindings for Fela
The npm package react-fela receives a total of 34,538 weekly downloads. As such, react-fela popularity was classified as popular.
We found that react-fela demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.