
Research
/Security News
Popular Tinycolor npm Package Compromised in Supply Chain Attack Affecting 40+ Packages
Malicious update to @ctrl/tinycolor on npm is part of a supply-chain attack hitting 40+ packages across maintainers
github.com/asoul-video/face-detection
Face detection for asoul.video image cover.
asoul.video 上的视频封面,展示时会将原本抖音上的封面图片居中裁剪为正方形。因此常常出现封面中的人物被截掉一半的情况。
因此,我们基于 https://github.com/nagadomi/lbpcascade_animeface 该项目实现的动漫人物面部捕捉,对每张封面图中人物面部进行定位并存储坐标。前端展示图片时根据人脸坐标对图片做相应的偏移。从而保证女孩们的脸始终居中。
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Malicious update to @ctrl/tinycolor on npm is part of a supply-chain attack hitting 40+ packages across maintainers
Security News
pnpm's new minimumReleaseAge setting delays package updates to prevent supply chain attacks, with other tools like Taze and NCU following suit.
Security News
The Rust Security Response WG is warning of phishing emails from rustfoundation.dev targeting crates.io users.