Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Node wrapper for OpenImageIO
This was created as part of an assignment for a computer graphics course.
This wrapper aims to allow reading and writing a wide variety of image formats via OpenImageIO.
No attempts are made to retain all data for floating point image formats. Everything is assumed to fit into UINT8 per channel per pixel.
var Image = require("node-oiio");
/* Pixel is likely not needed to be included.
It's what image.getPixel returns, which
is how you'll more likely work with it */
var Pixel = require("node-oiio/pixel");
var img = new Image('lena.png');
var smallImg = img.scale(50, 50);
smallImg.write('smalllena.png');
After you get libOpenImageIO you can simply npm install node-oiio
This library depends on libOpenImageIO being available. On
Gentoo emerge media-libs/openimageio
and node-gyp being
available should be sufficient.
If anyone wants to alter it so that it downloads and locally compiles OIIO to link against, that would probably be better.
FAQs
A simple OpenImageIO wrapper
The npm package node-oiio receives a total of 5 weekly downloads. As such, node-oiio popularity was classified as not popular.
We found that node-oiio demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.