Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Generate unique avatars of off your own image files!
Item
new Item(path, opts)
path
is the path to the imageopts
x
: Number
- x-coord to place the imagey
: Number
- y-coord to place the imagecheck
: Boolean
- check if the image can be foundreplace
: Array
of Object
's - filled with colors to replace from and to
from
: String
- color to replace from, in the format of r,g,b
- e.g. 128,128,128
to
: String
- color to replace to, in the format of r,g,b
- e.g. 128,128,128
Layer
new Layer(name, idx)
name
: String
- a friendly name to recogniseidx
: Number
- the z-index of the layerGenerator
new Generator(width, height, parentElm)
width
: Number
- width of the avatarheight
: Number
- height of the avatarparentElm
: Element
- element to place avatar withinFirst install my-avatars
by running npm i my-avatars
Now you'll need to import { Generator, Layer, Item }
from my-avatars
in your js
-file.
To build the generator, you'll have to have some images at hand. These should be made into Item
's, by new Item('./images/face.png')
.
Next, we'll need a Layer
: new Layer('faces', 0)
, this layer should have a name - for your own convenience - and an id, which can correspond to the z-index in css.
NB: No two layers can't have the same index.
Next-up, we'll need to pass in all of the Item
's, like so: faceLayer.addItem(item)
.
Now for the magical part, the Generator
. Start by creating a new Generator
, by new Generator(400, 400, app)
. Whereas the first 400
is the width of the avatar, next is the height and last argument is the parent element of, to which the avatar-canvas should be injected.
If all of this doesn't make sense. Check out the example
Check main.js, to run the example use npm run dev
. Or read this article
FAQs
Generate unique avatars of off your own image files!
The npm package my-avatars receives a total of 1 weekly downloads. As such, my-avatars popularity was classified as not popular.
We found that my-avatars demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.