Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
This repository hosts gioui.org/x
. Two kinds of package exist in this namespace. Some are extensions that will eventually be merged into gioui.org
's core repository once their APIs stabilize and their value to the community is proven. The rest are extensions to Gio that are not likely to be needed by every application and require new dependencies. These will likely never be merged to the core repository, but will be maintained here.
This table describes the current status of each package in gioui.org/x
:
Name | Purpose | Intended for core? | Non-core dependencies? | API Stability |
---|---|---|---|---|
colorpicker | Widgets for choosing colors | uncertain | no | unstable |
component | Material.io components | uncertain | no | unstable |
haptic | Haptic feedback for mobile devices | no | yes | unstable |
notify | Background notifications | no | yes | unstable |
outlay | Extra layouts | yes | no | unstable |
pref | Query user/device preferences | no | yes | unstable |
richtext | Printing text objects with different styles | uncertain | no | unstable |
explorer | Opening a native file dialog | uncertain | yes | unstable |
markdown | Rendering markdown text as richtext | uncertain | yes | unstable |
stroke | Complex stroked path support | no | no | unstable |
Report bugs on the gio issue tracker with the prefix gio-x:
in your issue title.
Ask questions on the gio discussion mailing list.
Send patches on the gio patches mailing list with the subject line prefix [PATCH gio-x]
All patches should be Signed-off to indicate conformance with the LICENSE of this repo.
Pre-1.0 tags are provided for reference only, and do not designate releases with ongoing support. Bugfixes will not be backported to older tags.
Tags follow semantic versioning. In particular, as the major version is zero:
This repository is primarily maintained by Chris Waldon.
Dual MIT/Unlicense; same as Gio
If gio provides value to you, please consider supporting one or more of its developers and maintainers:
Elias Naur: https://github.com/sponsors/eliasnaur
Chris Waldon: https://github.com/sponsors/whereswaldon https://liberapay.com/whereswaldon
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.