
Security News
npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders
npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback.
android-splash
Advanced tools
Get android splash screen files names and dimensions
The default splash screen image file names and required sizes for android are listed in a JSON file. This information is useful, for example, when you want to generate splash screen images with the required dimensons and/or to create a config.xml file for a PhoneGap/Cordova project or if you just need to create the splash screen images for your android project from one source image.
$ npm install --save android-splash
var splash = require('android-splash');
splash();
//=> [{"name":"GooglePlayFeature.png","width":1024,"height":500}, ...]
Returns an array of splash screen images, each image being represented by an object with name, width and height properties.
android-splash logs to stdout in comma-separated values format (csv) by default so you can easy pipe to other commands in UNIX systems.
$ npm install --global android-splash
$ android-splash --help
Usage: android-splash [options]
Options:
-h, --help, --help Show help
-f, --format format of the output to stdout (csv or json)
--fo, --format format of the output to stdout (csv or json)
--for, --format format of the output to stdout (csv or json)
--form, --format format of the output to stdout (csv or json)
--forma, --format format of the output to stdout (csv or json)
--he, --help Show help
--hel, --help Show help
Examples:
$ android-splash GooglePlayFeature.png,1024,500 ...
MIT © David Pfahler
FAQs
Get android splash screen files names and dimensions
The npm package android-splash receives a total of 11 weekly downloads. As such, android-splash popularity was classified as not popular.
We found that android-splash demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback.

Research
/Security News
Newer packages in this compromise use native extensions and .pth loaders to execute JavaScript stealers in developer environments.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.