npm-risk is a zero-dependency CLI that checks npm packages for basic supply-chain risk signals before you install them.
It looks at publish recency, install scripts, dependencies, maintainers, known vulnerabilities, and GitHub health, then gives you a simple LOW / MEDIUM / HIGH risk score.
Try it:
npx npm-risk
For more in-depth information:
https://medium.com/@Freedruk/npm...
This API wraps the Tropos engine. The Tropos engine is powering the Stratos Tokens App* by Team Sketch2React
Extract your Design Tokens from your Figma document as json data and use it for e.g:
- MaterialUI Theming
- CSS-in-JS
- input for Style Dictionary