Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
github.com/flutter/gallery
Flutter Gallery is a resource to help developers evaluate and use Flutter. It is a collection of Material Design & Cupertino widgets, behaviors, and vignettes implemented with Flutter. We often get asked how one can see Flutter in action, and this gallery demonstrates what Flutter provides and how it behaves in the wild.
The Flutter Gallery targets Flutter's master channel. As such, it can take advantage of new SDK features that haven't landed in the stable channel.
If you'd like to run the Flutter Gallery, make sure to switch to the master channel first:
flutter channel master
flutter upgrade
When you're done, use this command to return to the safety of the stable channel:
flutter channel stable
flutter upgrade
Flutter Gallery has been built to support multiple platforms. This includes:
An APK, macOS, Linux, and Windows builds are available for download. You can find it on the web at gallery.flutter.dev and on the Google Play Store.
You can build from source yourself for any of these platforms, though, please note desktop support must be enabled. For example, to run the app on Windows:
cd gallery/
flutter config --enable-windows-desktop
flutter pub get
flutter run -d windows
Additionally, the UI adapts between mobile and desktop layouts regardless of the platform it runs on. This is determined based on window size as outlined in adaptive.dart.
Convert your animation to a .gif
file.
Ideally, use a background color of 0xFF030303
to ensure the animation
blends into the background of the app.
Add your new .gif
file to the assets directory under
assets/splash_effects
. Ensure the name follows the format
splash_effect_$num.gif
. The number should be the next number after the
current largest number in the repository.
Update the map _effectDurations
in
splash.dart to include the number of the
new .gif
as well as its estimated duration. The duration is used to
determine how long to display the splash animation at launch.
If this is the first time building the Flutter Gallery, the localized
code will not be present in the project directory. However, after running
the application for the first time, a synthetic package will be generated
containing the app's localizations through importing
package:flutter_gen/gen_l10n/
.
See separate README for more details.
flutter pub get
flutter pub run grinder update-code-segments
See separate README for more details.
Version bump: Bump the pubspec.yaml
version number. This can be in a PR making a change or a separate PR.
Use semantic versioning to determine
which part to increment. The version number after the +
should also be incremented. For example 1.2.3+010203
with a patch should become 1.2.4+010204
.
Staging: After the version bump PR is merged, push a new version tag to master.
git pull upstream master
git tag v1.2.4 # note the v
git push upstream v1.2.4
This will trigger a set of GitHub Actions workflows that will:
Edit draft
-> Publish release
).prod
using GitHub's UI.promote_to_production
using GitHub's UI.More information about doing these things locally is available at go/flutter-gallery-manual-deployment.
The gallery has its own set of unit and integration tests. Flutter itself also uses it in tests. To enable breaking changes, the gallery version is pinned in two places:
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.