Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
react-vimeo
Advanced tools
var Vimeo = require('react-vimeo');
React.render(
<Vimeo videoId={ videoId } />,
$mountNode
);
To handle errors when something happens, like your video can't be loaded, you can pass a callback with a prop onError
in the component:
function onError(err) {
console.log(err);
};
React.render(
<Video onError={ onError } videoId={ videoId } />
document.querySelector('#your-div')
);
If you decide to use just Javascript without any module loader, you can get the global variable window.ReactVimeo
(or just ReactVimeo
):
There are some things that you should know about the component. The first one is the structure created inside by the component if you wish to stylize it.
So, the semantic HTML structure will be something like this:
<div class='vimeo'>
<div class='vimeo-loading'>
<svg>...</svg>
</div>
<div class='vimeo-image'>
<button type='button' class='vimeo-play-button'>
<svg>...</svg>
</button>
</div>
<div class='video-embed'>
<iframe>...</iframe>
</div>
</div>
This is a very simple structure to stylize however you want. So, if you are lost, don't panic, there is a real functional example that you can follow.
For more details, check out the API below.
<Video>
component:
Property | Type | Default | Required | Description |
---|---|---|---|---|
videoId | String | none | yes | The video ID |
onError | Function | noop | no | Callback function if the video can't be loaded |
MIT
See the License file.
FAQs
React component to load video from Vimeo
The npm package react-vimeo receives a total of 1,604 weekly downloads. As such, react-vimeo popularity was classified as popular.
We found that react-vimeo demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.