Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
tagliatelle-components
Advanced tools
To use this package in an app use the following command:
npm i tagliatelle-components -D
This package has tagliatelle-icons and tagliatelle-tokens as a dependency.
To create a new component please run the following command to generate the required files.
npm run generate-component
This command will require you to respond to two questions.
? Please select which category the new component belongs to? (Use arrow keys)
❯ atoms
molecules
organisms
? What is the component name? (please use camelCase)
You'll find your new component folder in the following directory packages/components/src/{category}
The new component folder will come with a *.stories.js
file ready so you can see the changes you make on Storybook.
Run npm run start
to launch Storybook on the browser at http://localhost:6006/.
A folder with four new files will be created;
To update the package with the changes you made, please commit your changes and run lerna version
.
Run npm run clean && npm run bootstrap
to update the package.json and commit your changes once more and then raise a PR.
After the review has been approved, build the package with npm run build
and then publish it to npm with lerna publish
.
FAQs
Front-end component library
The npm package tagliatelle-components receives a total of 126 weekly downloads. As such, tagliatelle-components popularity was classified as not popular.
We found that tagliatelle-components demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.