Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
@siteimprove/alfa-rectangle
Advanced tools
0.96.0 (2024-12-06)
@siteimprove/alfa-rules: A new experimental rule SIA-R115: "Heading is descriptive" is now available. (#1722)
@siteimprove/alfa-dom: An Element<"summary">#isSummaryForItsParentDetails
predicate is now available. (#1728)
@siteimprove/alfa-rules: SIA-R116: "<summary>
element has non-empty accessible name" is now available. (#1728)
@siteimprove/alfa-cache: A Cache.memoize
decorator is now available. (#1720)
@siteimprove/alfa-dom: An Attribute.Autocomplete
namespace is now available, grouping functionalities around the autocomplete
attribute. (#1724)
@siteimprove/alfa-rules, @siteimprove/alfa-aria: Expose allowedAttributes
on ARIA Element type. (#1721)
@siteimprove/alfa-aria: <summary>
elements that are not summary for their parent details are now correctly treated as generic
role. (#1728)
@siteimprove/alfa-aria: <details>
elements now correctly have an implicit role of group
. (#1728)
@siteimprove/alfa-device: Values of undefined user preferences are now correctly set to their default. (#1725)
@siteimprove/alfa-aria: <summary>
elements that are summary for their parent details now correctly have their name computed from content. (#1728)
@siteimprove/alfa-css-feature: Matching of user-preferences in the boolean context now correctly handles none
defaults. (#1725)
FAQs
Package for working with rectangles
The npm package @siteimprove/alfa-rectangle receives a total of 1,072 weekly downloads. As such, @siteimprove/alfa-rectangle popularity was classified as popular.
We found that @siteimprove/alfa-rectangle demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.