
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
lrm-graphhopper
Advanced tools
Extends Leaflet Routing Machine with support for GraphHopper.
Some brief instructions follow below, but the Leaflet Routing Machine tutorial on alternative routers is recommended.
Go to the releases page to get the script to include in your page. Put the script after Leaflet and Leaflet Routing Machine has been loaded.
To use with for example Browserify:
npm install --save lrm-graphhopper
There's a single class exported by this module, L.Routing.GraphHopper. It implements the IRouter interface. Use it to replace Leaflet Routing Machine's default OSRM router implementation:
var L = require('leaflet');
require('leaflet-routing-machine');
require('lrm-graphhopper'); // This will tack on the class to the L.Routing namespace
L.Routing.control({
router: new L.Routing.GraphHopper('your GraphHopper API key'),
}).addTo(map);
Note that you will need to pass a valid GraphHopper API key to the constructor.
To keep track of the GraphHopper credits consumption, the application may listen to the response event fired by the Router object. This event holds the values from GraphHopper's response HTTP headers:
status: The HTTP status code (see GraphHopper error codes)limit: The X-RateLimit-Limit headerremaining: The X-RateLimit-Remaining headerreset: The X-RateLimit-Reset headercredits: The X-RateLimit-Credits headervar router = myRoutingControl.getRouter();
router.on('response',function(e){
console.log('This routing request consumed ' + e.credits + ' credit(s)');
console.log('You have ' + e.remaining + ' left');
});
FAQs
Support for GraphHopper in Leaflet Routing Machine
The npm package lrm-graphhopper receives a total of 6,729 weekly downloads. As such, lrm-graphhopper popularity was classified as popular.
We found that lrm-graphhopper demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.