Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
@brightcove/videojs-flashls-swf
Advanced tools
The Flash-fallback video player for video.js (http://videojs.com)
The light-weight Flash video player that makes Flash work like HTML5 video. This allows player skins, plugins, and other features to work with both HTML5 and Flash
This project doesn't need to be used if you simply want to use the Flash video player. Head back to the main Video.js project if that's all you need, as the compiled SWF is checked in there.
npm install
grunt mxmlc
Production/ Distribution (runs mxmlc task and copies SWF to dist/):
grunt dist
grunt connect:dev
node_modules/flex-sdk/lib/flex_sdk/frameworks/flex-config.xml
<!-- Specifies the minimum player version that will run the compiled SWF. -->
<target-player>10.3</target-player>
<!-- Specifies the version of the compiled SWF -->
<swf-version>12</swf-version>
npm version {major,minor,patch}
npm publish
The swf and changelog will be automatically built and added to the repo on version.
** Note - We want to drop all of this for grunt based / Karma testing.
For unit tests, this project uses FlexUnit. The unit tests can be found in [project root]/src/com/videojs/test/
For integration tests, this project uses qunit. The integration tests can be found in [project root]/test
In order to run all of the tests, use the links at http://localhost:8000/index.html
There are very few tests. Adding to them is a fantastic and much appreciated way to contribute.
FAQs
The Flash-fallback video player for video.js (http://videojs.com)
The npm package @brightcove/videojs-flashls-swf receives a total of 147 weekly downloads. As such, @brightcove/videojs-flashls-swf popularity was classified as not popular.
We found that @brightcove/videojs-flashls-swf demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 84 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.