data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
A configurable jQuery plugin that allows you to tag images and so on.
Using npm:
npm install image-tags
Manually:
Simply download jquey.tags.js
from this repo and add it to your HTML. e.g.
Then include it after your jQuery file.
<script src="js/jquery.js"></script>
<script src="./js/jquery.tags.js"></script>
Optionally you can use include the css file as well.
<link href="css/tags.css" />
var options = {
// Aligning the text
align: {
x: 'center', // left, center or right
y: 'center' // top, center or bottom
},
// The (relative) offset of the popups in pixels
offset: {
left: -15, // horizontal offset
top: 20 // vertical offset
},
// event handlers of the tags
handlers: {
click: function(e) {
alert('You clicked a button');
this; // the DOM Node
e; // the Event
},
// Use 'show', 'hide' and 'toggle' to show/hide popups on mouse actions.
mouseenter: 'show', # Displays popup on mouseenter.
mouseleave: 'hide' # Hides popup on mouseleave.
}
// Whether to enable editor mode
edit: false,
// vote mode
//first edit:false must be false
//then
tagsType: 'radio',
radioBaseSize: 24,
// Strings for buttons
strings: {
save: '✓',
delete: '×'
addLink: '@'
}
};
// The magic comes together here
$('.taggd').taggd( options, data );
Data are the tags. Taggd accepts different formats, so pay close attention!
var data = [
// x and y values can be decimals (0-1)
{
x: 0.5,
y: 0.33,
text: 'test',
attributes: {
id: 'my-id',
class: 'my-class'
}
},
//vote mode
{
x: 0.5,
y: 0.33,
percent:0.6
text: 'iphone',
},
{
x: 0.15,
y: 0.8,
percent:0.4
text: 'android',
},
//link
{
x: 0.15,
y: 0.8,
link: 'http://gold.xitu.io/#/'
},
];
FAQs
A jQuery plugin that you can adds tags to your image.
The npm package image-tags receives a total of 0 weekly downloads. As such, image-tags popularity was classified as not popular.
We found that image-tags demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.