
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
dash-colorscales
Advanced tools
Add a fancy colorscale picker to your Dash apps. DashColorscales wraps react-colorscales for use in Dash.

Go to this link to learn about Dash.
pip install dash_colorscales
import dash_colorscales
import dash
import dash_html_components as html
import json
app = dash.Dash('')
app.scripts.config.serve_locally = True
app.layout = html.Div([
dash_colorscales.DashColorscales(
id='colorscale-picker',
nSwatches=7,
fixSwatches=True
),
html.P(id='output', children='')
])
@app.callback(
dash.dependencies.Output('output', 'children'),
[dash.dependencies.Input('colorscale-picker', 'colorscale')])
def display_output(colorscale):
return json.dumps(colorscale)
if __name__ == '__main__':
app.run_server(debug=True)
The DashColorscales component accepts these optional properties:
prop | Description |
|---|---|
id | Optional: Identifier used to reference component in callbacks |
colorscale | Optional: Default colorscale as an array of color strings (HEX or RGB). Defaults to viridis. |
nSwatches | Optional: Number of discrete colors or "swatches" in the default color scale. |
fixSwatches | Optional: If set to True, hides the swatches slider and fixes swatches to nSwatches. |
FAQs
Colorscale picker UI for your Dash apps
The npm package dash-colorscales receives a total of 2 weekly downloads. As such, dash-colorscales popularity was classified as not popular.
We found that dash-colorscales demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.