
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
exif-orientation
Advanced tools
Returns the exif orientation in scale / rotation from a file object
npm install exif-orientation --save
The following example reacts to the onChange event of a file upload html input
var findOrientation = require('exif-orientation');
fileUpload.addEventListener('change',function(e) {
var file = e.target.files[0];
findOrientation(file,function(err,orientation) {
if (!err) {
console.log(orientation); // displays {scale: {x: 1, y: 1}, rotation: 90}
}
});
});
findOrientation(file,callback)file A file object from a file upload html input
callback A function to be called once the orientation data is found or an error occured. The callback is passed 2 arguments (err,orientation). If err is undefined, orientation will contain the orientation data, otherwise err will be an Error object with the message of the error.
MIT, see LICENSE.md for details.
FAQs
Returns the exif orientation is scale / rotation from a file object
The npm package exif-orientation receives a total of 632 weekly downloads. As such, exif-orientation popularity was classified as not popular.
We found that exif-orientation demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.