
Security News
Next.js Patches Critical Middleware Vulnerability (CVE-2025-29927)
Next.js has patched a critical vulnerability (CVE-2025-29927) that allowed attackers to bypass middleware-based authorization checks in self-hosted apps.
@eclipse-glsp/sprotty
Advanced tools
A web-based diagram client framework for the Graphical Language Server Platform (GLSP) based on Eclipse Sprotty.
This project is built with yarn
and is available from npm via @eclipse-glsp/client.
For more information, please visit the Eclipse GLSP Umbrella repository and the Eclipse GLSP Website. If you have questions, please raise them in the discussions and have a look at our communication and support options.
@eclipse-glsp/protocol
package has no default dependency to inversify #384#387GLSPMousePositionTracker
correctly calculates the current position in diagram local coordinates #391ActionDispatcher
interface with GLSPActionDispatcher
implementation. #394
GLSPActionDispatcher
is no longer necessary use TYPES.IActionDispatcher
/ActionDispatcher
insteadcopyPasteStandalone
module to ensure that copy/cut/paste listeners are scoped to the active diagram and don't trigger globally #395IMovementOptions
for the ChangeBoundsTool
to allow configuration of movement behavior #397 - Contributed on behalf of Axon Ivy AGChangeBoundsTool
from working correctly if the user moved outside of the diagram during an operation #399 - Contributed on behalf of AxonIvy AGGLSPClient
implementation to be more robust when certain methods are invoked multiple times #402NavigationTargetResolver
#403GridManger
to TYPES.IGridManager
, ChangeBoundsManager
to TYPES.IChangeBoundsManager
and DebugManager
to TYPES.IDebugManager
.postRequestModel
hook to actually work as descried in the documentation.
Dispatching of long running actions in this hook can delay the initial model loading.preInitialize
hook is discouraged.
If needed dispatch an action instead.
This ensures that the code will only be called once the model is available.FAQs
Augmented reexport of the sprotty API for GLSP
We found that @eclipse-glsp/sprotty demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Next.js has patched a critical vulnerability (CVE-2025-29927) that allowed attackers to bypass middleware-based authorization checks in self-hosted apps.
Security News
A survey of 500 cybersecurity pros reveals high pay isn't enough—lack of growth and flexibility is driving attrition and risking organizational security.
Product
Socket, the leader in open source security, is now available on Google Cloud Marketplace for simplified procurement and enhanced protection against supply chain attacks.