Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@squarespace/fonts-loaded
Advanced tools
A promise-based class used to determine if fonts have loaded for particular HTMLElements.
NOTICE: This code is licensed to you pursuant to Squarespace’s Developer Terms of Use. See license section below.
npm install --save @squarespace/fonts-loaded
const fontsLoadedInstance = new fontsLoaded([HTMLElement, HTMLElement]);
fontsLoadedInstance.check().then(...)
If you prefer to handle transpiling and polyfilling on your own, you can import ES6 from Fonts Loaded:
import FontsLoaded from '@squarespace/fonts-loaded/src';
Alternately, Fonts Loaded specifies a module
property in package.json
that points to the uncompiled src/index.js
, so you may be able to simply import @squarespace/fonts-loaded
if you're using one of the following bundlers:
Params
Array
- An array of HTMLElements. The font-family of these elements will be tested to determine if the font has loaded.Begins to check if the fonts have loaded and returns a promise.
Clears timers and removes test elements.
Portions Copyright © 2016 Squarespace, Inc. This code is licensed to you pursuant to Squarespace’s Developer Terms of Use, available at http://developers.squarespace.com/developer-terms-of-use (the “Developer Terms”). You may only use this code on websites hosted by Squarespace, and in compliance with the Developer Terms. TO THE FULLEST EXTENT PERMITTED BY LAW, SQUARESPACE PROVIDES ITS CODE TO YOU ON AN “AS IS” BASIS WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED.
FAQs
Determine if fonts are loaded for particular nodes
We found that @squarespace/fonts-loaded demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 15 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.