
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
react-md-magic
Advanced tools
A simple yet powerful and extensible React Markdown Editor. React-mde has no 3rd party dependencies. Min + Gzipped package is around 9KB.
npm i react-mde
React-mde is agnostic regarding how to preview Markdown. The examples will use Showdown
npm install showdown
from version 7.4, it is also possible to return a Promise to React Element from
generateMarkdownPreview, which makes it possible to use ReactMarkdown as a preview. View issue.
React-mde is a completely controlled component.
Minimal example using Showdown. View live on CodeSandBox:
import * as React from "react";
import ReactMde from "react-mde";
import ReactDOM from "react-dom";
import * as Showdown from "showdown";
import "react-mde/lib/styles/css/react-mde-all.css";
const converter = new Showdown.Converter({
tables: true,
simplifiedAutoLink: true,
strikethrough: true,
tasklists: true
});
export default function App() {
const [value, setValue] = React.useState("**Hello world!!!**");
const [selectedTab, setSelectedTab] = React.useState("write");
return (
<div className="container">
<ReactMde
value={value}
onChange={setValue}
selectedTab={selectedTab}
onTabChange={setSelectedTab}
generateMarkdownPreview={markdown =>
Promise.resolve(converter.makeHtml(markdown))
}
/>
</div>
);
}
React-mde comes with SVG icons extracted from FontAwesome included.
You can customize the way icons are resolved by passing your own getIcon that will return a ReactNode
given a command name.
<ReactMde
getIcon={(commandName) => <MyCustomIcon name={commandName} />}
onChange={this.handleValueChange}
// ...
/>
The types are described below
onChange event.CommandGroup, which, each one, contain a commands property (array of Command). If no commands are specified, the default will be used. Commands are explained in more details below.prop is falsy, then no preview is going to be generated.iconProvider to allow custom icon rendering.
options. It is recommended to inspect the layouts source code to see what options can be passed to each
while the documentation is not complete.textarea component.write and preview.The following styles from React-mde should be added: (Both .scss and .css files are available. No need to use sass-loader if you don't want)
Easiest way: import react-mde-all.css:
import 'react-mde/lib/styles/css/react-mde-all.css';
If you want to have a more granular control over the styles, you can import each individual file.
If you're using SASS, you can override these variables: https://github.com/andrerpena/react-mde/blob/master/src/styles/variables.scss
React-mde does not automatically sanitize the HTML preview. If your using Showdown, this has been taken from their documentation:
Cross-side scripting is a well known technique to gain access to private information of the users of a website. The attacker injects spurious HTML content (a script) on the web page which will read the user’s cookies and do something bad with it (like steal credentials). As a countermeasure, you should filter any suspicious content coming from user input. Showdown doesn’t include an XSS filter, so you must provide your own. But be careful in how you do it…
You might want to take a look at showdown-xss-filter.
Starting from version 7.4, it is also possible to return a Promise to a React Element from
generateMarkdownPreview, which makes it possible to use ReactMarkdown as a preview. View issue. ReactMarkdown has built-in XSS protection.
You can create your own commands or reuse existing commands. The commands property of React-mde
expects an array of CommandGroup, which contains an array of commands called commands. You can also
import the existing commands as displayed below:
import ReactMde, {commands} from "react-mde";
const listCommands = [
{
commands: [
commands.orderedListCommand,
commands.unorderedListCommand,
commands.checkedListCommand
]
}
]
<ReactMde
commands={listCommands}
...
/>
Please refer to the commands source code to understand how they should be implemented.
React-mde is MIT licensed.
In order to make React-mde zero deps, I've embedded two small libraries:
Made with :heart: by André Pena and other awesome contributors. Check out my website: http://andrerpena.me.
FAQs
React Markdown Editor
We found that react-md-magic demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.