
Security News
Package Maintainers Call for Improvements to GitHub’s New npm Security Plan
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
@kartotherian/osm-bright-style
Advanced tools
A fork of Mapbox's style of the same name, intended for Kartotherian. This style relies on the osm-bright.tm2source datasource. Vanilla Mapbox vector tiles are not fully supported.
node_modules/osm-bright-fonts
subdirectorynode_modules/osm-bright-fonts
subdirInstall Mapbox Studio Classic (version 0.3.4 only!) ATTENTION: versions 0.3.5 - 0.3.7 are broken, and will not display correct colors. To get an older version, right click on the download link, copy it, and change the version to 0.3.4.
Use this approach if you have git and Node.js npm to automatically download fonts from the fonts repository.
git clone https://github.com/kartotherian/osm-bright.tm2.git
cd osm-bright.tm2
npm install
If you have Postgres with OSM database on your machine, and you want to experiment with the datasource itself, install it and set the source
value in the project.yml
to its location (relative paths are not supported):
source: "tmsource:///Users/msemenik/dev/osm/osm2pgsql-osm-bright.tm2source"
See Mapbox Studio Classic installation notes above.
FAQs
A CartoCSS map style for Kartotherian tile service
We found that @kartotherian/osm-bright-style demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 8 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
Product
Socket Firewall is a free tool that blocks malicious packages at install time, giving developers proactive protection against rising supply chain attacks.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.