
Security News
OWASP 2025 Top 10 Adds Software Supply Chain Failures, Ranked Top Community Concern
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.
@jupyterlab/commenting-extension
Advanced tools
Installation | Development | License | Team | Getting help |

We have articulated our vision for this project as a "Press Release from the Future". We are now pursing that vision to make it a reality. Have feedback or want to get involved? Post an issue!
Check out the Usage Guide to learn about the features this extension offers.
jupyter labextension install @jupyterlab/commenting-extension
To contribute to the project, please read the contributor documentation.
JupyterLab Commenting and Annotation follows the Jupyter Community Guides.
JupyterLab Commenting and Annotation uses a shared copyright model that enables all contributors to maintain the copyright on their contributions. All code is licensed under the terms of the revised BSD license.
JupyterLab Commenting Extension is part of Project Jupyter and is developed by an open community.
Current maintainers of this project are listed in alphabetical order, with affiliation, and main areas of contribution:
We encourage you to ask questions on the mailing list, and participate in development discussions or get live help on Gitter. Please use the issues page to provide feedback or submit a bug report.
FAQs
A JupyterLab extension to support commenting and annotation.
The npm package @jupyterlab/commenting-extension receives a total of 2 weekly downloads. As such, @jupyterlab/commenting-extension popularity was classified as not popular.
We found that @jupyterlab/commenting-extension demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 21 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.