Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
@huggingface/tasks
Advanced tools
This package contains the definition files (written in Typescript) for the huggingface.co hub's:
Please add any missing ones to these definitions by opening a PR. Thanks 🔥
⚠️ The hub's definitive doc is at https://huggingface.co/docs/hub.
This package also contains data used to define https://huggingface.co/tasks.
The Task pages are made to lower the barrier of entry to understand a task that can be solved with machine learning and use or train a model to accomplish it. It's a collaborative documentation effort made to help out software developers, social scientists, or anyone with no background in machine learning that is interested in understanding how machine learning models can be used to solve a problem.
The task pages avoid jargon to let everyone understand the documentation, and if specific terminology is needed, it is explained on the most basic level possible. This is important to understand before contributing to Tasks: at the end of every task page, the user is expected to be able to find and pull a model from the Hub and use it on their data and see if it works for their use case to come up with a proof of concept.
You can open a pull request to contribute a new documentation about a new task. Under src/tasks
we have a folder for every task that contains two files, about.md
and data.ts
. about.md
contains the markdown part of the page, use cases, resources and minimal code block to infer a model that belongs to the task. data.ts
contains redirections to canonical models and datasets, metrics, the schema of the task and the information the inference widget needs.
We have a dataset
that contains data used in the inference widget. The last file is const.ts
, which has the task to library mapping (e.g. spacy to token-classification) where you can add a library. They will look in the top right corner like below.
This might seem overwhelming, but you don't necessarily need to add all of these in one pull request or on your own, you can simply contribute one section. Feel free to ask for help whenever you need.
FAQs
List of ML tasks for huggingface.co/tasks
We found that @huggingface/tasks demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.