
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@threlte/core
Advanced tools
Threlte is a Svelte library that simplifies creating 3D apps for the web. It provides a declarative, type-safe, reactive and interactive API out-of-the-box.
Threlte's 3D rendering is powered by Three.js, and it also provides a physics engine through Rapier and an animation studio via Theatre.js; see packages for details.
Check out our documentation and our Discord community.
@threlte/core provides declarative and transparent Svelte binding to Three.js.
This package is the heart of the Threlte library. It's an excellent starting point for those learning Threlte for the first time.
For a quick interactive setup of a fresh Threlte project, run:
npm create threlte my-project
Alternatively you can check out the full installation instructions.
To get a hang of the basics, we recommend following our introductory tutorial.
Have questions? Feel free to ask in our Discord support forum.
Clean API transparently exposing all Three.js objects through declarative API.
Hooks providing easy access to low-level contexts like animation frames and the rendering engine.
Plugins making it easy to extend Threlte with custom code and logic.
Events enabling robust and Svelte-native access to state transformations in your scenes.
Interactivity makes it easy to react to user inputs on 3D objects.
Contributions are what make the open source community such an amazing place to learn, inspire, and create. Any contributions you make are greatly appreciated.
The MIT License (MIT). Please see the License File for more information.
FAQs
A 3D framework for the web, built on top of Svelte and Three.js
The npm package @threlte/core receives a total of 4,792 weekly downloads. As such, @threlte/core popularity was classified as popular.
We found that @threlte/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.