
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
react-signal
Advanced tools
Send messages between components.
You might not want to use this.
If you need to share state between two components, then lift that state up to some common ancestor and pass the state as props. If that common ancestor is too far up in your tree, then you can use context to share that state without having to do prop drilling.
So when should you use this?
Use this when you want to send some kind of message from one component to another, without having that message rest in state somewhere.
Using npm:
npm install react-signal
Using yarn:
yarn add react-signal
import { createSignal } from 'react-signal';
import React from 'react';
const Signal = createSignal();
function Publisher() {
const publish = Signal.usePublish();
return <button onClick={() => publish('hello')}>Click me</button>;
}
function Subscriber() {
Signal.useSubscription((message) => {
console.log('Received: ', message);
});
return <p>Check the console</p>;
}
function App() {
return (
<Signal.Provider>
<Publisher />
<Subscriber />
</Signal.Provider>
);
}
Please feel free to submit any issues or pull requests.
Thank you Francisco Morais for your huge help with the logo!
MIT
FAQs
Send messages between components.
We found that react-signal demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.