Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
tailwind-gradient-mask-image
Advanced tools
A plugin for Tailwind CSS for masking elements using mask-image and linear-gradient.
Tailwind CSS plugin for adding mask-image
with a linear-gradient
on a HTML element.
Try it out in Tailwind CSS Playground
With npm
npm install tailwind-gradient-mask-image
With yarn
yarn add tailwind-gradient-mask-image
Add the plugin to your tailwind.config.js
{
plugins: [require("tailwind-gradient-mask-image")]
}
<div class="gradient-mask-t-0">
...
</div>
The plugin creates classes with prefix gradient-mask-
. After the prefix follows a direction shorthand and the gradient start percentage.
The class above matches the css
.class {
mask-image: linear-gradient(to top, rgba(0, 0, 0, 1.0) 0%, transparent 100%);
}
Using
gradient-mask-none
will set the CSS property tomask-image: none
. This can be used in combination of breakpoints for device-specific behaviors
Direction shorthands
{
t: "to top",
tr: "to top right",
r: "to right",
br: "to bottom right",
b: "to bottom",
bl: "to bottom left",
l: "to left",
tl: "to top left",
}
The gradient start percentages go from 0% to 100% with 10% gaps.
You can use arbitrary values to specify unique steps towards a specific direction
<div class="gradient-mask-t-[transparent,rgba(0,0,0,1.0)_30px,rgba(0,0,0,0.5)_40%]">
...
</div>
The class above matches the following css
.class {
mask-image: linear-gradient(to top, transparent, rgba(0,0,0,1.0) 30px, rgba(0,0,0,0.5) 40%, transparent 100%)
}
A transparent at 100% will always be set to keep a specific direction
You can always add
transparent_80%
at the end of your abitrary value to have the last 20% fully masked
FAQs
A plugin for Tailwind CSS for masking elements using mask-image and linear-gradient.
We found that tailwind-gradient-mask-image demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.