
Research
SANDWORM_MODE: Shai-Hulud-Style npm Worm Hijacks CI Workflows and Poisons AI Toolchains
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.
obelix-plugin-typography
Advanced tools
A Typography.js plugin for Obelix
This Obelix plugin generates a stylesheet based on a Typography.js configuration or theme.
Install into your project (or globally if you prefer):
npm install --save obelix-plugin-typography
If you plan on using a Typography.js theme, install that too.
Then in your obelix.edn file, configure the plugin:
{:plugins
{:obelix-plugin-typography
{:fileName "typography.css" ;; The name of the generated CSS file, defaults to typography.css
:theme "typography-theme-fairy-gates" ;; Optional, the Typography.js theme to use
;; In addition or instead of a theme, specify any Typography.js
;; options you want. These will override the theme settings.
:baseFontSize 16
:baseLineHeight 1.5
;; etc.
}}}
Important: This plugin only generates the typography stylesheet. You still need to add a <link> to it in the layouts or pages you want it to be applied to.
FAQs
A typography.js plugin for the Obelix static site generator
We found that obelix-plugin-typography demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.

Company News
Socket is proud to join the OpenJS Foundation as a Silver Member, deepening our commitment to the long-term health and security of the JavaScript ecosystem.

Security News
npm now links to Socket's security analysis on every package page. Here's what you'll find when you click through.