Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
crunchitize
Advanced tools
Crunchitize is a tool to assist in making Crunch compressed DXT textures. It currently converts PNG images, and by default makes them pre-multiplied to be friendly to pixi.js. If it finds a .json file with the same name as a converted .png, it also modifies that json file's meta.image
property to point at the new texture file instead of the (assumed) png. Crunchitize can resize your images for you, but the output texture must have dimensions that are each a multiple of 4.
-f, --files Glob path or path to .txt file list of glob paths to .pngs to process.
-q, --quality Quality of crunch output, 0-1. Default is 0.5.
-pm, --premultiplied If the input pngs should be converted to premultiplied alpha images first. Default is true.
-n, --noise Strength of noise to apply to image before processing, from 0-1 (small numbers suggested). Default is 0.
--format 'crn' for .crn, or 'dds' for .dds. Default is 'crn'.
-d, --deleteInput If the input pngs should be deleted after being converted. Default is false.
-r, --resize How to resize input images to be multiple of 4 dimensions. Options are 'scale' to scale up, 'border' to add transparency to the right and bottom. The default is to not resize, and skip invalid images.
crunchitize -f path/to/my.png
crunchitize -f path/to/folder/ -q 1
crunchitize -f path/to/folder/ --format dds
list.txt:
path/to/my.png 0.8
path/to/other.png 0.3 scale
path/to/another.png border
shell:
crunchitize -f path/to/list.txt
Executables for the crunch compression itself are taken from https://github.com/BKcore/crunch-osx.
FAQs
Turn images into Crunch textures (.crn)
The npm package crunchitize receives a total of 6 weekly downloads. As such, crunchitize popularity was classified as not popular.
We found that crunchitize demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.