Security News
PyPI’s New Archival Feature Closes a Major Security Gap
PyPI now allows maintainers to archive projects, improving security and helping users make informed decisions about their dependencies.
wonderbly-components
Advanced tools
https://wonderbly-components.herokuapp.com/
This package is a unit tested bundle of reusable components built in React. Wonderbly website-v2 consumes these components via npm for example:
import Tag from "wonderbly-components/lib/Tag";
<Tag backgroundColor="#7077CC">I'm a tag</Tag>;
The site repo also displays component examples via react-styleguidist.
yarn install
yarn start
# fire up styleguide locally
yarn test
# run mocha + enzyme unit tests
yarn test:watch
# rerun tests on file changes
yarn styleguide:copy-assets
# styleguidist requires fonts as static assets from wonderbly-css
# styleguide/assets/** is ignored so these must be copied once per clean install
yarn styleguide:build
# build styleguide locally to ./styleguide-build/
yarn build
# removes ./lib folder and rebuilds production files
yarn watch
# reruns build on file changes
# should be used for local yarn linked development
yarn lint
# lint ./src/
yarn lint:fix
# fix your bad typing
npm publish
# builds and publishes the package
npm version [<newversion> | major | minor | patch
npm publish
package.json
of website-v2Use the #deployment channel to deploy master on slack:
/h deploy wonderbly-components to production
You can also deploy a branch like this:
/h deploy wonderbly-components/chore/gw_deploy-styleguide to production
If you're working on the website and want to see changes from wonderbly-components on local website.
# in wonderbly-components register packages with yarn
yarn link
# react must be linked due to react hooks
cd node_modules/react
yarn link
# in website-v2
yarn link wonderbly-components
yarn link react
# in wonderbly-components rebuild on file change
yarn watch
FAQs
The home of all of Wonderbly's reusable React Components
The npm package wonderbly-components receives a total of 109 weekly downloads. As such, wonderbly-components popularity was classified as not popular.
We found that wonderbly-components demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 8 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
PyPI now allows maintainers to archive projects, improving security and helping users make informed decisions about their dependencies.
Research
Security News
Malicious npm package postcss-optimizer delivers BeaverTail malware, targeting developer systems; similarities to past campaigns suggest a North Korean connection.
Security News
CISA's KEV data is now on GitHub, offering easier access, API integration, commit history tracking, and automated updates for security teams and researchers.