
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
tailwind-variance
Advanced tools
Affected versions:
[![Build status][build-image]][build-url] [![Tests coverage][cov-image]][cov-url] [![npm version][npm-image]][npm-url]
tailwind-variance is a powerful Tailwind CSS theme preset that helps teams build
scalable, maintainable, and cohesive design systems.
It provides structured theme tokens, extensible foundations, and flexible customization options—ideal for ensuring UI consistency across products and brands.
🎨 Unified Theme Tokens
Predefined colors, typography, spacing, radii, shadows, and sizing scales for consistent UI.
🧱 Design-System Foundations
Built-in architecture for reusable components and UI primitives.
🧩 Plugin & Preset Friendly
Fully compatible with the Tailwind ecosystem (plugins, presets, custom layers).
⚙️ Effortless Customization
Extend or override tokens directly from your existing tailwind.config.js.
🪶 Zero Dependencies
No runtime code; pure Tailwind config for high scalability.
npm install tailwind-variance --save-dev
# or
yarn add tailwind-variance --dev
FAQs
tailwind-variance
The npm package tailwind-variance receives a total of 0 weekly downloads. As such, tailwind-variance popularity was classified as not popular.
We found that tailwind-variance demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.