Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
drawbotics-blog-theme
Advanced tools
This is the default blog theme for Drawbotics.
## Setting up
You must first clone the Ghost repository https://github.com/TryGhost/Ghost, install packages npm install
and run the project with npm start
in the cloned folder. Then navigate to http://localhost:2368/ghost
(default port).
The Ghost blog comes with a standard Casper theme, which can be found in the folder content/themes/casper
. We now need to set the Drawbotics Blog Theme as the blog theme.
Go to the folder content/themes
in the ghost blog folder cloned previously, and once there clone this repo. You can then navigate to the Ghost admin page http://localhost:2368/ghost
and in General, set the theme for the blog. You should see the drawbotics-blog-theme
there, and activate it.
You can then create some content to access the Post and Author pages. By default, each Post should have only 1 tag (or category) assigned to it, and a meta description of maximym 140 characters. An Author should have a profile picture, a short bio and a location (to be used as their Job title).
While in the content/themes/drawbotics-blog-theme
directory, run
$ npm i && npm start
This will start a Gulp watcher for all the files in your src
folder, compiling .less into a minified css, .js into a minified js bundle, as well as images and fonts which are used in the theme.
After starting the Gulp assets builder, remember to restart the Ghost server, as it won't recognise changes otherwise.
FAQs
Theme for the Drawbotics blog
The npm package drawbotics-blog-theme receives a total of 4 weekly downloads. As such, drawbotics-blog-theme popularity was classified as not popular.
We found that drawbotics-blog-theme demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.