npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

sgh-carousel

v0.1.0

Published

Angular carousel component with security hardening

Readme

SghCarousel

A secure Angular carousel/dialog component for displaying content with navigation controls.

Features

  • Modal-based carousel display
  • Keyboard navigation (Arrow keys)
  • Previous/Next navigation buttons
  • Customizable content display
  • Security hardened (v0.1.0+)

Installation

npm install sgh-carousel

Usage

Basic Usage

import { MatDialog } from '@angular/material/dialog';
import { SghCarouselComponent, SghCarouselData } from 'sgh-carousel';

@Component({...})
export class MyComponent {
  constructor(private dialog: MatDialog) {}

  openCarousel(): void {
    const carouselData: SghCarouselData = {
      title: 'My Carousel',
      content: '<div>Your HTML content here</div>',
      totalRecords: 5,
      selectedRecord: 1,
      navigateStatus: true,
      prevCallBack: () => this.onPrevious(),
      afterCallBack: () => this.onNext()
    };

    this.dialog.open(SghCarouselComponent, {
      data: { sghCarouselData: carouselData }
    });
  }

  onPrevious(): void {
    // Handle previous navigation
  }

  onNext(): void {
    // Handle next navigation
  }
}

Interfaces

// Carousel data configuration
interface SghCarouselData {
  prevCallBack: () => void;      // Previous navigation callback
  afterCallBack: () => void;     // Next navigation callback
  title: string;                 // Carousel title
  totalRecords: number;          // Total items count
  selectedRecord: number;        // Current item index (1-based)
  content: string;               // HTML content (sanitized automatically)
  navigateStatus: boolean;       // Enable keyboard navigation
}

// Dialog data wrapper
interface SghCarouselDialogData {
  sghCarouselData: SghCarouselData;
}

Security Features (v0.1.0+)

This library includes comprehensive security hardening:

  • XSS Prevention: All HTML content is sanitized using Angular's DomSanitizer with SecurityContext.HTML
  • Safe Event Handling: Uses Angular's @HostListener instead of global document event handlers
  • Input Validation: Dialog data is validated before use
  • Type Safety: Replaced any types with proper TypeScript interfaces
  • Callback Protection: Callbacks are wrapped in try-catch with validation
  • Proper Cleanup: Implements OnDestroy for proper lifecycle management

Build

Run ng build sgh-carousel to build the project. The build artifacts will be stored in the dist/ directory.

Publishing

After building your library with ng build sgh-carousel, go to the dist folder cd dist/sgh-carousel and run npm publish.

Running unit tests

Run ng test sgh-carousel to execute the unit tests via Karma.

Version History

| Angular Version | Library Version | Description | |-----------------|-----------------|-------------| | 16 | 0.0.5 | Initial release | | 17 | 0.0.6 | Angular 17 support | | 18 | 0.0.7 | Angular 18 support | | 19 | 0.0.8 | Angular 19 support | | 19 | 0.1.0 | Security Hardening - XSS prevention, safe event handling, type safety |

Changelog v0.1.0 - Security Hardening

  • Fixed: XSS vulnerability via innerHTML - Content now sanitized with DomSanitizer
  • Fixed: Global event handler pollution - Replaced document.onkeydown with @HostListener
  • Fixed: Unsafe any type usage - Added proper TypeScript interfaces
  • Fixed: Uncontrolled function execution - Callbacks wrapped with validation and try-catch
  • Added: OnDestroy lifecycle hook for proper cleanup
  • Added: Input validation for dialog data
  • Added: ARIA labels for accessibility
  • Added: ngDevMode checks for development-only logging
  • Improved: Type exports in public API

License

MIT