Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
gray-percentage
Advanced tools
Convenience function to get a gray value by percentage e.g. gray(60) -> hsla(0,0%,100%,0.4)
Convenience function to get a gray value by percentage e.g. gray(60) -> "hsla(0,0%,100%, 0.4)"
The function takes a required "lightness" value from 0-100 and an optional second parameter to mixin color to the gray value. The second parameter can either be a "hue" value from 0-360 or one of three named hues, "cool", "slate", and "warm".
As suggested by Google Material Design we color lightness using opacity instead of gray values. Quoting Google: "Black or white text that is transparent remains legible and vibrant against background color changes. This makes it more flexible than grey text in the same contexts."
We assume when picking the opacity/lightness that the background is
light. If, for example, you have dark background with light text, set
the third paramter, darkBackground
to true e.g. gray(80, 0, true)
.
We use color theory to choose an appropriate saturation value. Basically the darker the gray, the higher the saturation value that is choosen. This article was very helpful in picking appropriate saturation values http://ianstormtaylor.com/design-tip-never-use-black/
The following is the curve that choose saturation values and is used here in the code.
npm install gray-percentage
var gray = require('gray-percentage');
var textColor = gray(30);
// textColor = "hsla(0,0%,100%,0.7)"
// Get a "cool" gray.
var background = gray(93, "cool")
// background = "hsla(237,0.9935851860000025%,100%,0.07)"
// Mixin arbitrary hues e.g. Red.
var sidebarBg = gray(15, 360)
// sidebarBg = "hsla(360,14.84301465%,100%,0.85)"
// Get color for dark background
var lightGray = gray(85, 0, true)
// lightGray = "hsla(0, 0%, 100%, 0.85)"
FAQs
Convenience function to get a gray value by percentage e.g. gray(60) -> hsla(0,0%,100%,0.4)
The npm package gray-percentage receives a total of 8,313 weekly downloads. As such, gray-percentage popularity was classified as popular.
We found that gray-percentage demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.