
Security News
Next.js Patches Critical Middleware Vulnerability (CVE-2025-29927)
Next.js has patched a critical vulnerability (CVE-2025-29927) that allowed attackers to bypass middleware-based authorization checks in self-hosted apps.
metalsmith-tweet-embed
Advanced tools
Metalsmith plugin for converting twitter status URLS to an embedded tweet
Converts Twitter status URLS to embedded Twitter statuses
With npm:
npm install metalsmith-tweet-embed
With yarn:
yarn add metalsmith-tweet-embed
var metalsmith = require('metalsmith');
var tweetEmbed = require('metalsmith-tweet-embed');
metalsmith(__dirname)
.use(tweetEmbed())
.build();
You can limit which status links get converted by passing in pattern
as a param.
var metalsmith = require('metalsmith');
var tweetEmbed = require('metalsmith-tweet-embed');
metalsmith(__dirname)
.use(tweetEmbed({ pattern: '**/*.md' }))
.build();
You can also customize the options of the embed by using any options supported by the Twitter Status oEmbed API.
These options can be set directly from the plugin, or via frontmatter.
From Frontmatter
---
title: Look at this awesome page
twitter:
omit_script: false
align: center
---
This is my markdown content
https://twitter.com/BillGates/status/7957453193
From Plugin
var metalsmith = require('metalsmith');
var tweetEmbed = require('metalsmith-tweet-embed');
metalsmith(__dirname)
.use(tweetEmbed({
options: {
omit_script: true,
align: 'center'
}
}))
.build();
Any embed options set via frontmatter will overwrite options set from the plugin options.
FAQs
Metalsmith plugin for converting twitter status URLS to an embedded tweet
The npm package metalsmith-tweet-embed receives a total of 0 weekly downloads. As such, metalsmith-tweet-embed popularity was classified as not popular.
We found that metalsmith-tweet-embed demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Next.js has patched a critical vulnerability (CVE-2025-29927) that allowed attackers to bypass middleware-based authorization checks in self-hosted apps.
Security News
A survey of 500 cybersecurity pros reveals high pay isn't enough—lack of growth and flexibility is driving attrition and risking organizational security.
Product
Socket, the leader in open source security, is now available on Google Cloud Marketplace for simplified procurement and enhanced protection against supply chain attacks.