Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@roast-cms/image-froth
Advanced tools
A tool to help query the right responsive image with preset dimensions.
🥛 Prevent jumping content while loading responsive images with Cloudinary
If you don't want your page to jump every time a new image is starting to load you need to let the browser know the height of your images ahead of time. Otherwise it's assumed that the height is 0, which rapidly and unexpectedly changes as the real data about its dimensions comes in. This makes reading and interacting with content a frustrating task for the users.
If you are using a responsive image system (where you have multiple image versions for various screen sizes) along with flexible image dimensions (i.e.: width: 100%
) things get complicated.
This tool solves this issue by adopting a simple image naming system and generating all the necessary data your browser needs to know to tame your content pages.
# first you'll need the package:
yarn add @roast-cms/image-froth
This tool is built to be used with Cloudinary image management service, though you can easily adopt it to work with whatever image storage tool you use.
You will, however, have to change the way you name your image files to:
image-froth_1500000_BJ7LbcnLG.jpg
...where _150000_
is the image ratio that you will need to calculate when uploading the image using this formula: Math.round((width/height)*1000000)
, and BJ7LbcnLG
is a random alphanumeric string to avoid clashing file names. image_froth
prefix and image ratio number are mandatory, though you can name your files what you like, random string is just a suggestion.
The simplest use is getting a Cloudinary image URL along with ratio data from the filename:
froth(
{
// image file without extension
src: "image-froth_1500000_BJ7LbcnLGb",
},
{
server: "https://res.cloudinary.com/analog-cafe/image/upload/",
transformations: "",
sizes: {
"image-s": "480", // (this is required)
"image-m": "640",
},
// placeholder image src (in this case it's a white dot)
placeholder:
"",
}
);
// will return:
// {
// height: 320
// width: 480
// ratio: 1.5
// src: "https://res.cloudinary.com/analog-cafe/image/upload/c_scale,fl_progressive,w_480/image-froth_1500000_BJ7LbcnLGb.jpg"
// type: "jpg"
// }
A bit more complicated but a real-world scenario. Below is an example of how the tool is used on Analog.Cafe blog using React:
<picture
style={{
// padding-bottom is a CSS trick that's used to set responsive image ratios
// without distorting the image width as the screen is resized:
padding-bottom:
`${
// extracting the image ratio...
froth({ src: "image-froth_1500000_BJ7LbcnLG.jpg" }).ratio
// converting it to CSS-readable percent
? Math.round(100 / froth({ src: "image-froth_1500000_BJ7LbcnLG.jpg" }).ratio, 3)
: 0
}%`
}}
>
<source
srcSet={
froth({
// this is wht we'd store in the database as image URL for this document;
// instead of full URL address, it'll be simply the image reference
// in the form described above:
src: "image-froth_1500000_BJ7LbcnLG.jpg",
// here you can choose a pre-determined image size (see below):
size: "image-s"
// `froth()` will return the full image URL:
}).src
}
media="(max-width: 480px)"
/>
<source
srcSet={froth({ src: "image-froth_1500000_BJ7LbcnLG.jpg", size: "image-l" }).src}
media="(min-width: 1201px)"
/>
<img
src={froth({ src: "image-froth_1500000_BJ7LbcnLG.jpg", size: "image-l" }).src}
style={{
// going along with the above CSS trick for padding-bottom rule
height: froth({ src }).ratio ? "100%" : "initial"
}}
/>
</picture>
// additionally other image formats could be requested within <picture /> element
// using { type: "webp" } option, for example.
PRs and issue reports are welcome. Please submit all PRs to develop
branch. To test, run yarn dev
FAQs
A tool to help query the right responsive image with preset dimensions.
The npm package @roast-cms/image-froth receives a total of 22 weekly downloads. As such, @roast-cms/image-froth popularity was classified as not popular.
We found that @roast-cms/image-froth demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.