
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
@jsonforms/material-tree-renderer
Advanced tools
Supply Chain Security
Vulnerability
Quality
Maintenance
License
JSONForms eliminates the tedious task of writing fully-featured forms by hand by leveraging the capabilities of JSON, JSON Schema and Javascript.
This repository contains a re-usable tree component that renders a tree-master-detail JSON editor. The repository contains an IDE webcomponent that additionally configures 3 buttons to access the data shown in the tree:
Additionally, the package contains a small runtime demo showing an editor for users and tasks.
Run npm install
to install dependencies.
Run npm run build
to build the module. The build results are located in /dist/
.
Run npm run dev
to start the standalone editor. It is available at http://localhost:8080/
The JSONForms project is licensed under the MIT License. See the LICENSE file for more information.
Our current roadmap is available here.
JSONForms is developed by EclipseSource. We are always very happy to have contributions, whether for trivial cleanups or big new features.
If you are already using JSONForms 1, check our migration guide.
FAQs
Material-based tree renderer for JSON Forms
The npm package @jsonforms/material-tree-renderer receives a total of 17 weekly downloads. As such, @jsonforms/material-tree-renderer popularity was classified as not popular.
We found that @jsonforms/material-tree-renderer demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.