Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
A legible & concise status badge solution for third-party codebase services.
Make your own badges here!
Many GitHub repos sport badges for things like:
As you can see from the zoomed 400% versions of these badges above, nobody is (really) using the same badge file and at normal size, they're hardly legible. Worst of all, they're completely inconsistent. The information provided isn't of the same kind on each badge. The context is blurry, which doesn't make for a straightforward understanding of how these badges are relevant to the project they're attached to and what information they provide.
As you can see below, without increasing the footprint of these badges, I've tried to increase legibility and coherence, removing useless text to decrease the horizontal length in the (likely) scenario that more of these badge thingies crop up on READMEs all across the land.
We have an effort to produce similar-looking SVGs through a web service at http://img.shields.io. That ensures that we are retina-ready.
What kind of meta data can you convey using badges?
build | failing
coverage | 80%
version | 1.2.3
gem | 1.2.3
dependencies | out-of-date
code climate | 3.8
semver | 2.0.0
tips | $2/week
See SPECIFICATION.md.
See INSTALL.md.
See CONTRIBUTING.md.
See LICENSE.md.
FAQs
Shields.io badge library
The npm package gh-badges receives a total of 83 weekly downloads. As such, gh-badges popularity was classified as not popular.
We found that gh-badges demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.