
Research
Using Trusted Protocols Against You: Gmail as a C2 Mechanism
Socket uncovers malicious packages on PyPI using Gmail's SMTP protocol for command and control (C2) to exfiltrate data and execute commands.
tfstyleguide
Advanced tools
The style guide contains common elements (core.less) as well as shared variables and mixins (vars.less) used by Thinkful apps.
This style guide is available on NPM
. In your package.json
file, add this:
dependencies: {
...
'tfstyleguide': '^v6.1.0'
To use the styleguide, you need two imports into your own LESS
files.
In your entry-point (the file that references all your other LESS
files), add this line at the top. core.less
includes a CSS reset and
default typography & input styles. It should not be imported more than
once, or the styles will be duplicated.
import "../../node_modules/tfstyleguide/core";
In most of your other files, you will want to start with this line. You
can import vars.less
more than once:
import "../../node_modules/tfstyleguide/vars";
This will let you use the styleguide's media queries, color variables, and mixins in your app's LESS files.
To keep the styleguide up-to-date, run npm update tfstyleguide
before
your asset-building scripts like gulp
. This will download and install
the latest version.
Occasionally we release a version of the style guide for sites that do not use LESS. The current version is available at:
https://tf-assets-prod.s3.amazonaws.com/styleguide_lts/styleguide_4.0.9_LTS.min.css
Update your local LESS and run
lessc core.less > release/styleguide_vN.N.N_LTS.css
lessc -x core.less > release/styleguide_vN.N.N_LTS.min.css
Then upload those to S3 under the folder styleguide_lts
https://www.thinkful.com/styleguide-demo
Copyright 2018 Thinkful Inc.
FAQs
LESS Style Guide for thinkful.com
The npm package tfstyleguide receives a total of 27 weekly downloads. As such, tfstyleguide popularity was classified as not popular.
We found that tfstyleguide demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious packages on PyPI using Gmail's SMTP protocol for command and control (C2) to exfiltrate data and execute commands.
Product
We redesigned Socket's first logged-in page to display rich and insightful visualizations about your repositories protected against supply chain threats.
Product
Automatically fix and test dependency updates with socket fix—a new CLI tool that turns CVE alerts into safe, automated upgrades.