
Security News
OWASP 2025 Top 10 Adds Software Supply Chain Failures, Ranked Top Community Concern
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.
@ryersonlibrary/building-info-system
Advanced tools
An information and wayfinding web application for buildings.
RULA-BIS is an open source web application designed to provide directory, wayfinding and other informational services for buildings using the latest web technologies.
Currently the application contains a number of features:
Currently the application is provided as a single bundle and can be installed by either cloning this repo or by using NPM:
git clone git@https://github.com/ryersonlibrary/building-info-system.git my-bis
or
npm i --save @ryersonlibrary/building-info-system
The system fetches the information it needs from a number of external sources. Primary among theses is a data API that provides all the details about most of the aspects of the system (buildings, floors, and mapped elements, wayfinding, images, FAQ text, and more). This API needs to be setup configured separately. The data specification that this application needs will be outlined below. Other features like the events require an external ICAL file.
There are a number of API enpoints that are used by the system. Each endpoint
should provide GET functionality which, when called, returns a list of objects
in a JSON format. All the endpoints should be relative to a common host e.g. api.example.com.
The details of the API and the objects expected, along with their fields, will be added later.
FAQs
An information and wayfinding web application for buildings.
We found that @ryersonlibrary/building-info-system demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.