Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@apostrophecms/nunjucks
Advanced tools
This fork of Nunjucks 2.x is maintained by the ApostropheCMS team as part of long term support for ApostropheCMS 2.x. There will be no new features or intentional changes in behavior. We recommend the latest version of the mainstream Nunjucks release for new projects, and plan to use that in future versions of ApostropheCMS that require a templating language.
Our maintenance modifications, if any, are released under the same license as Nunjucks 2.x.
Nunjucks is a full featured templating engine for javascript. It is heavily inspired by jinja2. View the docs here.
npm install @apostrophecms/nunjucks
(View the CHANGELOG) through 2.5.2. An additional changelog will be added here as neded for maintenance updates.
See here. NOTE: this is a legacy version (2.x) and not all 3.x documentation may be relevant.
Supported in all modern browsers. For IE8 support, use es5-shim.
Run the tests with npm test
.
Watch master
branch's tests running at http://mozilla.github.io/nunjucks/files/tests/browser/.
Join our mailing list and get help with and issues you have: https://groups.google.com/forum/?fromgroups#!forum/nunjucks
FAQs
2.x maintenance fork of Nunjucks templating language
The npm package @apostrophecms/nunjucks receives a total of 84 weekly downloads. As such, @apostrophecms/nunjucks popularity was classified as not popular.
We found that @apostrophecms/nunjucks demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 13 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.