
Security News
Socket Releases Free Certified Patches for Critical vm2 Sandbox Escape
A critical vm2 sandbox escape can allow untrusted JavaScript to break isolation and execute commands on the host Node.js process.
@dogstudio/highway
Advanced tools

Highway is a lightweight (2.5ko compressed & gzipped), robust, modern and flexible library that will let us create AJAX navigations with beautiful transitions on our websites. It's been a while we were trying to build this kind of library to fits our needs at Dogstudio and we now finally released it!
Highway is supported by all recent major versions of the following modern browsers.
Older browsers or versions can be supported by Highway by combining it with polyfills. Please follow this example to have more information. Once the polyfills are configured, Highway should be working on most of the browsers and versions. However, be aware that the oldest browsers or versions might still be unsupported. So, be reasonable before opening an issue...
trigger information in transitions and eventsCore.redirect(href, transition) methodCore.attach(links) methodCore.detach(links) methodfrom and to parameters of the NAVIGATE_END eventCore.redirect(href) methodCore.bind() into Core.attach()Core.unbind() into Core.dettach()Renderer.root into Renderer.viewRenderer.page by Renderer.propertiesNAVIGATE_IN event that was fired too earlyNAVIGATE_ERROR eventdist/es5 folderBasic Anchor exampleBasic Polyfill exampleinit method to setup methodjavascript: in hrefNAVIGATE_CALL, NAVIGATE_IN, NAVIGATE_OUT eventsHighway.RendererHighway.TransitionSee the LICENSE file for license rights and limitations (MIT).
FAQs
Highway helps you manage your page transitions
The npm package @dogstudio/highway receives a total of 81 weekly downloads. As such, @dogstudio/highway popularity was classified as not popular.
We found that @dogstudio/highway demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
A critical vm2 sandbox escape can allow untrusted JavaScript to break isolation and execute commands on the host Node.js process.

Research
Five malicious NuGet packages impersonate Chinese .NET libraries to deploy a stealer targeting browser credentials, crypto wallets, SSH keys, and local files.

Security News
pnpm 11 turns on a 1-day Minimum Release Age and blocks exotic subdeps by default, adding safeguards against fast-moving supply chain attacks.