Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
connect-fonts-alegreyasans
Advanced tools
Alegreya Sans Black fontpack for connect-fonts.
const font_middleware = require("connect-fonts");
const font_pack = require("connect-fonts-alegreyasans");
setup
function. app.use(font_middleware.setup({
fonts: [ font_pack ],
allow_origin: "https://exampledomain.com"
}));
<link href="/alegreyasans-black/fonts.css" type="text/css" rel="stylesheet"/ >
Multiple fonts from the family can be included by using a comma separated list of fonts:
<link href="/alegreyasans-black,alegreyasans-blackitalic,alegreyasans-bold,alegreyasans-bolditalic,alegreyasans-extrabold,alegreyasans-extrabolditalic,alegreyasans-italic,alegreyasans-light,alegreyasans-lightitalic,alegreyasans-medium,alegreyasans-mediumitalic,alegreyasans-regular,alegreyasans-thin,alegreyasans-thinitalic/fonts.css" type="text/css" rel="stylesheet"/ >
Available fonts:
Locale-optimised font sets can be served by specifying the locale in the fonts.css URL.
<link href="/latin/alegreyasans-black/fonts.css" type="text/css" rel="stylesheet"/ >
Available subsets:
body {
font-family: 'Alegreya Sans Black', 'sans-serif', 'serif';
}
Alegreya Sans
Software: Licenced under version 2.0 of the MPL
Fonts: Licensed under version 1.1 of the SIL Open Font License
FAQs
Alegreya Sans Black font pack for connect-fonts
The npm package connect-fonts-alegreyasans receives a total of 2 weekly downloads. As such, connect-fonts-alegreyasans popularity was classified as not popular.
We found that connect-fonts-alegreyasans demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.