
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
react-timespan
Advanced tools
A neat timeline component that displays a gallery of activities with a pannable plot.

The display precision is based on year, which is a large unit. Sorting precision is down to the millisecond.
import Timeline from 'react-timespan';
const activities = [
{
name: 'Cole Turner',
start: '1991-02-24',
url: 'http://cole.codes/',
body: 'As a baby I was born because something about birds and bees.',
image: 'http://...'
},
{
name: 'The Year I Wrote This',
start: '2017-01-01',
end: '2017-12-31',
url: 'http://cole.codes/',
body: 'Truly I made this for my portfolio and decided to sh are.',
image: 'http://...'
}
];
<Timeline activities={activities} />
A SASS stylesheet is included separately...
I decided to share this because I am fond of the end result and hope it will inspire a pull request to make it better.
Pull requests are warmly welcomed.
Cole Turner
FAQs
Timeline component with gallery view and scrolling time plots.
The npm package react-timespan receives a total of 3 weekly downloads. As such, react-timespan popularity was classified as not popular.
We found that react-timespan demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.