Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@gemini-testing/canvas-prebuilt
Advanced tools
Prebuilt versions of node-canvas as a drop-in replacement
This fork is only for install
script fix in 1.6.x version: https://github.com/node-gfx/node-canvas-prebuilt/pull/13
This is a drop-in replacement for canvas that does not require any compiling. To use it
just npm install canvas-prebuilt
or replace canvas
with canvas-prebuilt
in your
dependencies.
You will also need to change require('canvas')
to require('canvas-prebuilt')
.
The repo is just a set of scripts that downloads a specific node-canvas version, builds it and bundles it on all platforms. It's meant to run on Travis and AppVeyor but it can be run locally too
Linux users will need glibc >= 2.13.1 (Ubuntu 14.04+, Debian 7+, etc)
If you are using fonts, you might see some FontConfig warnings which are harmless:
Situation | Message | Meaning |
---|---|---|
You have an old version of FontConfig on your system | Fontconfig warning: line 142: blank doesn't take any effect anymore. please remove it from your fonts.conf | You don't need to do anything, but removing said line or upgrading FontConfig on your system should fix it |
You don't have FontConfig | Fontconfig error: Cannot load default config file | You don't have any fonts on your system, so if you want to use the text APIs you'll either need to install FontConfig or use Canvas.registerFont |
More detail on the releases below, this won't be relevant to most users.
Make sure your node version is the most recent to guarantee ABI compatibility
canvas@1.4.x canvas@1.5.x canvas@1.6.x canvas@2.0.0-alpha.1 canvas@2.0.0-alpha.2 canvas@2.0.0-alpha.3 | node 8 | node 7 | node 6 | node 5 | node 4 | node 0.12 | node 0.10 |
---|---|---|---|---|---|---|---|
Linux x64 | โ | โ | โ | โ | โ | โ | โ |
Windows x64 | โ | โ | โ | โ | โ | โ | โ |
OSX x64 | โ | โ | โ | โ | โ | โ | โ |
Windows x86 | ๐ยน | ๐ยน | ๐ยน | ๐ยน | ๐ยน | ๐ยน | ๐ยน |
Linux x86 | ๐ยน | ๐ยน | ๐ยน | ๐ยน | ๐ยน | ๐ยน | ๐ยน |
Linux ARM | ๐ยน | ๐ยน | ๐ยน | ๐ยน | ๐ยน | ๐ยน | ๐ยน |
canvas@2.0.0-alpha.3 canvas@2.0.0-alpha.4 canvas@2.0.0-alpha.5 | node 9 | node 8 | node 7 | node 6 | node 5 | node 4 |
---|---|---|---|---|---|---|
Linux x64 | โ | โ | โ | โ | โ | โ |
Windows x64 | โ | โ | โ | โ | โ | โ |
OSX x64 | โ | โ | โ | โ | โ | โ |
Windows x86 | ๐ยน | ๐ยน | ๐ยน | ๐ยน | ๐ยน | ๐ยน |
Linux x86 | ๐ยน | ๐ยน | ๐ยน | ๐ยน | ๐ยน | ๐ยน |
Linux ARM | ๐ยน | ๐ยน | ๐ยน | ๐ยน | ๐ยน | ๐ยน |
ยนI have some ideas on how to get these working with cross-compilation if people request it. I plan to add Linux/ARM
The bundling scripts just take a regularly compiled executable (canvas.node in this case) and look at which non-system libraries it links against. Those libraries are then copied to the release directory and binaries are updated if necessary to refer to them.
The strategies for bundling could be applied to other projects too since they're general:
/lib
is non-system. The custom binding.gyp
compiles canvas.node
to look inside its own directory for dependenciesFAQs
Prebuilt versions of node-canvas as a drop-in replacement
We found that @gemini-testing/canvas-prebuilt demonstrated a not healthy version release cadence and project activity because the last version was released a year ago.ย It has 5 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.