Security News
Research
Supply Chain Attack on Rspack npm Packages Injects Cryptojacking Malware
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
@jupyterlab/statusbar
Advanced tools
4.1.0
defaultPath
option to set the default directory for file dialog #15282 (@mmichilot)processedItemsCache
as a protected in CompleterModel
#15025 (@krassowski)filebrowser.open
and add ability to provide a factory #14983 (@fcollonval)copyAbsolutePath
enabling to copy absolute path #14842 (@pauky)overrides.json
not working for shortcuts #15716 (@krassowski)user
level or to none (as fallback) #15678 (@krassowski)Ctrl
+ Enter
#15638 (@krassowski)hash
from jupyter-server
v2.11.1+ #15577 (@Wh1isper)Tab
#15571 (@krassowski)jupyter labextension watch --help
#15542 (@akx)level
trait for plugin/extension managers #15512 (@krassowski)FormComponent
showing error indicators in all fields when using a customValidate
function #15464 (@mmichilot)defaultPath
, and model disposal #15463 (@mmichilot)overrides.json
#15346 (@LJMP)require.resolve()
#15299 (@tibdex)Shift + Enter
#15288 (@krassowski)full
windowed mode #15286 (@krassowski)unusedDocuments
, fix culling of foreign documents #15105 (@krassowski)getMimeTypeByLanguage()
#15101 (@krassowski)<select>
elements in dark theme #15098 (@Rmarieta)_updateConstraints
missing protected
/private
classifier. #15066 (@krassowski)HoverBox
: adjust right
when moving node to fit within window #15052 (@krassowski)shouldShowContinuousHint()
#15015 (@krassowski)staging/yarn.lock
#14926 (@fcollonval)serverCapabilities
, provides
, and updateLogging
#14712 (@krassowski)context.contentsModel.content
#14660 (@fcollonval)ifaxity/wait-on-action
wrapper with direct wait-on
use #15721 (@krassowski)pytest-tornasync
to pytest-jupyter
#15662 (@KiranmaiKalla)jlpm
as npm client for snapshot updates #15641 (@krassowski)page.filebrowser.refresh()
timeout logic #15607 (@jtpio)actions/upload-artifact@v4
and action/download-artifact@v4
#15536 (@jtpio)ipython
in dependabot updates #15528 (@jtpio)pull_request_review
#15523 (@jtpio)actions/labeler
to v4 to fix failing CI action #15496 (@krassowski)--collaborative
is used without jupyter-collaboration
#15300 (@mdengler)@jupyterlab/rendermime-interfaces
to 3.9.0-alpha.1
#15240 (@jtpio)@jupyter/ydoc
1.1.1 #15177 (@jtpio)|
#15072 (@krassowski)getEditorIndexAt()
method #15028 (@krassowski)| null
to the mermaid plugin activate parameter #15003 (@jtpio)default_url
configurable #14944 (@jtpio)Event.IManager
interface #14770 (@trungleduc)StatusMessage
which is dead code #14713 (@krassowski)jupyter labextension list
compat message #14680 (@jtpio)OSTYPE
check in ci_install.sh
#11801 (@jtpio)level
trait for plugin/extension managers #15512 (@krassowski)Notification.dismiss
#15197 (@krassowski)README.md
#15039 (@jtpio)--UNSAFE
flag in the extension tutorial docs #15007 (@jtpio)staging/yarn.lock
#14926 (@fcollonval)copyAbsolutePath
enabling to copy absolute path #14842 (@pauky)good first issue
label #14686 (@krassowski)jupyter labextension list
compat message #14680 (@jtpio)(GitHub contributors page for this release)
@afshin | @akx | @alden-ilao | @AllanChain | @andrewfulton9 | @andrii-i | @ashna1jain | @bikash30851 | @blink1073 | @bollwyvl | @brichet | @brijsiyag | @coriegulik | @davidbrochart | @DcWire | @Deepali1211 | @DenisaCG | @dependabot | @dharmaquark | @divyansshhh | @dolevf | @DonJayamanne | @echarles | @eliaslma | @emmanuel-ferdman | @ericsnekbytes | @fcollonval | @firai | @FoSuCloud | @g547315 | @gabalafou | @GabrielaVives | @github-actions | @HaudinFlorence | @hbcarlos | @holzman | @isabela-pf | @j264415 | @jans-code | @JasonWeill | @jtpio | @jupyterlab-bot | @jupyterlab-probot | @KiranmaiKalla | @krassowski | @LJMP | @lumberbot-app | @m158261 | @mctoohey | @mdengler | @MFA-X-AI | @misterfads | @mlucool | @mmichilot | @nbowditch-einblick | @nishikantparmariam | @paolocarinci | @parmentelat | @pauky | @paulkim3151 | @phil-zxx | @pre-commit-ci | @Rmarieta | @RRosio | @Sarthug99 | @sinistersnare | @skyetim | @smacke | @SylvainCorlay | @t03857785 | @tibdex | @timkpaine | @tonyfast | @trungleduc | @welcome | @Wh1isper | @yuvipanda
FAQs
JupyterLab statusbar package.
The npm package @jupyterlab/statusbar receives a total of 42,817 weekly downloads. As such, @jupyterlab/statusbar popularity was classified as popular.
We found that @jupyterlab/statusbar demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 11 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.
Security News
Sonar’s acquisition of Tidelift highlights a growing industry shift toward sustainable open source funding, addressing maintainer burnout and critical software dependencies.