
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
the sixel PR has been merged upstream (since r31), go use that. If you were previously using this fork, just set sixel true and no other change is needed, if you have trouble with migrating from this fork, open an issue here.
This is a fork of lf with support for sixel graphics.
Sixel support requires a sixel-capable terminal and is only available on Unix systems (only tested on Linux but BSD distributions and MacOS should work).

Sixel sequences can be passed directly to lf for displaying, cleaning, and caching. An example config based on cirala's lfimg can be found here. For those managing their own previewer:
chafa "$1" -f sixel -s "$(($2-2))x$3" in your previewer scriptexit 0, any other exit code indicates that the user's previewer and cleaner scripts will handle cleaning and caching.Google Groups | Wiki | #lf (on Libera.Chat) | #lf:matrix.org (with IRC bridge)
This is a work in progress. Use at your own risk.
lf (as in "list files") is a terminal file manager written in Go with a heavy inspiration from ranger file manager.
See faq for more information and tutorial for a gentle introduction with screencasts.

mkdir, touch, chmod, chown, chgrp, and ln)See releases for pre-built binaries.
Building from the source requires Go.
On Unix:
env CGO_ENABLED=0 go install -ldflags="-s -w" github.com/horriblename/lf@latest
On Windows cmd:
set CGO_ENABLED=0
go install -ldflags="-s -w" github.com/horriblename/lf@latest
On Windows powershell:
$env:CGO_ENABLED = '0'
go install -ldflags="-s -w" github.com/horriblename/lf@latest
After the installation lf command should start the application in the current directory.
Run lf -help to see command line options.
Run lf -doc to see the documentation.
See etc directory to integrate lf to your shell and/or editor.
Example configuration files along with example colors and icons files can also be found in this directory.
See integrations to integrate lf to other tools.
See tips for more examples.
See contributing for guidelines.
FAQs
Unknown package
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.