
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
react-keybinding
Advanced tools
Declarative, lightweight, and robust keybindings mixin for React.
'⌘S' string syntax for declaring bindingskeybinding method of that component'⌘S' on Mac to '^S' on Windows)Install with npm and use in your React projects with either browserify or webpack.
$ npm install react-keybinding
var React = require('react'),
Keybinding = require('../');
var HelloMessage = React.createClass({
mixins: [Keybinding],
keybindingsPlatformAgnostic: true,
keybindings: {
'⌘S': function(e) {
console.log('save!');
e.preventDefault();
},
'⌘C': 'COPY'
},
keybinding: function(event, action) {
// event is the browser event, action is 'COPY'
console.log(arguments);
},
render: function() {
return React.createElement("div", null, "Hello");
}
});
React.render(React.createElement(HelloMessage, {name: "John"}), document.body);
There's a runnable example in the ./examples directory: to run it,
$ npm install
$ cd example
$ npm install
$ npm start
See tmcw/ditty for an example of react-keybinding in an application.
This module exposes a single mixin called Keybinding.
Where you use this mixin on Components, it expects a property called
keybindings of the format:
keybindings: {
// keys are strings: they can contain meta and shift symbols,
// numbers, strings, etc
'⌘S': function(e) {
// bindings can map to functions that they call directly
},
// or to constants that are passed to the component's
// 'keybinding' method.
'⌘C': 'COPY'
}
Platform agnostic keybindings will automatically listen for the 'Ctrl'
equivalent of 'Cmd' keybindings, and vice-versa. To automatically coerce
platform specific keybindings, provide a property called
keybindingsPlatformAgnostic of the format:
keybindingsPlatformAgnostic: true,
keybindings: { ... }
The mixin provides a method for components called .getAllKeybindings():
this yields an array of all keybindings properties on all active components.
The full range of codes and modifiers supported is listed in SYNTAX.md.
$ npm test
FAQs
declarative, concise keybindings for react
We found that react-keybinding demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 43 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.