
Security News
Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline, Forces Certificate Rotation
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.
figma-parser
Advanced tools
Work in progress! Parse Figma design files via Figma API to design tokens
Each token has to be a single layer following a specific naming (besides that, organise and style your design file as you want):
color-xxx with fill as the token valuespace-xxx with height as the token valuefont-family-xxx with font family set as token valuefont-style-xxx with font size and weight set as token valueicon-xxx with the vector icon shape as the first child layerillustration-xxx with the vector illustration as the first child layerThe token can also be a group named by the rules. The style will be read by the last (bottom most) layer of the group.
Here's an example file - https://www.figma.com/file/s3DjttpILZzr4LC6WrkJun/Dark-theme?node-id=0%3A1
const FigmaParser = require("figma-parser");
const figma = new FigmaParser({
token: "your-access-token"
});
(async () => {
// Parse all tokens
const output = await figma.parse("figma-file-id");
// Parse optional tokens
const output = await figma.parse("figma-file-id", ["colors", "space", "fonts", "fontSizes", "fontWeights"]);
// Raw JSON file
console.log(output);
// Markup as JSON
console.log(figma.markup("json"));
// Markup as Typescript definitions
console.log(figma.markup("ts"));
// Pass custom markup template, see /lib/templates.ts
console.log(figma.markup("your-custom-template"));
})();
FAQs
Parse Figma design files via Figma API
The npm package figma-parser receives a total of 43 weekly downloads. As such, figma-parser popularity was classified as not popular.
We found that figma-parser demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.

Security News
Open source is under attack because of how much value it creates. It has been the foundation of every major software innovation for the last three decades. This is not the time to walk away from it.

Security News
Socket CEO Feross Aboukhadijeh breaks down how North Korea hijacked Axios and what it means for the future of software supply chain security.