Security News
New Python Packaging Proposal Aims to Solve Phantom Dependency Problem with SBOMs
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.
@hmcts/one-per-page
Advanced tools
Easily build GOV.UK style one question per page services using express, nunjucks and webpack.
One per page solves a number of hard problems in building a one question per page service:
All documentation is available at https://one-per-page.herokuapp.com
Add one-per-page and look-and-feel to your package.json:
> yarn add @hmcts/one-per-page @hmcts/look-and-feel
Then create a few steps and wire them to your express app:
app.js
const app = express();
class Start extends EntryPoint {
next() {
return goTo(this.journey.steps.CheckYourAnswers);
}
}
class Name extends Question {
get form() {
return form({
firstName: text.joi('Enter your first name', Joi.string().required()),
lastName: text.joi('Enter your last name', Joi.string().required()),
});
}
next() {
return goTo(this.journey.steps.CheckYourAnswers);
}
}
journey(app, {
steps: [
Start,
Name,
CheckYourAnswers
]
});
app.listen(3000);
And create a template for your step:
Name.template.html
{% extends "look-and-feel/layouts/question.html" %}
{% from "look-and-feel/components/fields.njk" import textbox %}
{% set title %}What is your name?{% endset %}
{% block fields %}
{{ textbox(fields.firstName, "First Name") }}
{{ textbox(fields.lastName, "Last Name") }}
{% endblock %}
@hmcts/look-and-feel
helps with creating templates
Then start your app:
> node app.js
# listening on port 3000
This project is open to accepting contributions. Check out our open issues for ideas on where to start or to raise your own issue. Read our development documentation for help on getting started.
FAQs
One question per page apps made easy
The npm package @hmcts/one-per-page receives a total of 13 weekly downloads. As such, @hmcts/one-per-page popularity was classified as not popular.
We found that @hmcts/one-per-page demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.
Security News
Socket CEO Feross Aboukhadijeh discusses open source security challenges, including zero-day attacks and supply chain risks, on the Cyber Security Council podcast.
Security News
Research
Socket researchers uncover how threat actors weaponize Out-of-Band Application Security Testing (OAST) techniques across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.