Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
@turf/tag is a module within the Turf.js library that allows you to tag points with properties from polygons. This is particularly useful for geospatial analysis where you need to associate point data with the regions they fall into.
Tagging Points with Polygon Properties
This feature allows you to tag points with properties from polygons they fall into. In this example, points are tagged with the 'name' property from the polygons.
const turf = require('@turf/turf');
const points = turf.points([
[-77, 44],
[-77, 38],
[-77, 39]
]);
const polygons = turf.featureCollection([
turf.polygon([[[-80, 41], [-70, 41], [-70, 39], [-80, 39], [-80, 41]]], { name: 'polygon1' }),
turf.polygon([[[-80, 45], [-70, 45], [-70, 43], [-80, 43], [-80, 45]]], { name: 'polygon2' })
]);
const taggedPoints = turf.tag(points, polygons, 'name', 'polygonName');
console.log(taggedPoints);
Geolib is a library for geospatial calculations. It provides functions for distance calculations, finding points within a radius, and more. Unlike @turf/tag, it does not specifically focus on tagging points with polygon properties but offers a broader range of geospatial utilities.
Leaflet is a popular open-source JavaScript library for mobile-friendly interactive maps. While it provides extensive functionalities for map visualization and interaction, it does not offer built-in support for tagging points with polygon properties like @turf/tag.
JSTS is a JavaScript library of spatial predicates and functions for processing geometry. It is more focused on geometric operations and spatial analysis, providing a different set of functionalities compared to @turf/tag.
Takes a set of points and a set of polygons and/or multipolygons and performs a spatial join.
points
FeatureCollection<Point> input pointspolygons
FeatureCollection<(Polygon | MultiPolygon)> input (multi)polygonsfield
string property in polygons
to add to joined {} featuresoutField
string property in points
in which to store joined property from polygons
var pt1 = turf.point([-77, 44]);
var pt2 = turf.point([-77, 38]);
var poly1 = turf.polygon([[
[-81, 41],
[-81, 47],
[-72, 47],
[-72, 41],
[-81, 41]
]], {pop: 3000});
var poly2 = turf.polygon([[
[-81, 35],
[-81, 41],
[-72, 41],
[-72, 35],
[-81, 35]
]], {pop: 1000});
var points = turf.featureCollection([pt1, pt2]);
var polygons = turf.featureCollection([poly1, poly2]);
var tagged = turf.tag(points, polygons, 'pop', 'population');
//addToMap
var addToMap = [tagged, polygons]
Returns FeatureCollection<Point> points with containingPolyId
property containing values from polyId
This module is part of the Turfjs project, an open source module collection dedicated to geographic algorithms. It is maintained in the Turfjs/turf repository, where you can create PRs and issues.
Install this single module individually:
$ npm install @turf/tag
Or install the all-encompassing @turf/turf module that includes all modules as functions:
$ npm install @turf/turf
FAQs
turf tag module
The npm package @turf/tag receives a total of 635,547 weekly downloads. As such, @turf/tag popularity was classified as popular.
We found that @turf/tag demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 9 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.