
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@patarapolw/markdown-it-imsize
Advanced tools
A markdown-it plugin for size-specified image markups. This plugin overloads original image renderer of markdown-it.
var md = require('markdown-it')({
html: true,
linkify: true,
typography: true
}).use(require('markdown-it-imsize')); // <-- this use(package_name) is required

is interpreted as
<p><img src="image.png" alt="test" width="100" height="200"></p>
var md = require('markdown-it')({
html: true,
linkify: true,
typography: true
}).use(require('markdown-it-imsize'), { autofill: true });
will fill the width and height fields automatically if the specified image path is valid.
Therefore,

is interpreted as
<p><img src="image.png" alt="test" width="200" height="200"></p>
where image.png is a valid path and its size is 200 x 200.
markdown-it-imsize is available with bower and RequireJS. First, you can install the package with,
bower install markdown-it-imsize
Script for using markdown-it-imsize with RequireJS is like,
require(['require', 'MarkdownIt', 'MarkdownItImsize'], function(require) {
var md = require('MarkdownIt')({
html: true,
linkify: true,
typography: true
}).use(require('MarkdownItImsize'));
var rendered = md.render("");
document.getElementById('image-box').innerHTML = rendered;
});
FAQs
Markdown-it plugin to specify image size
We found that @patarapolw/markdown-it-imsize demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.