
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
opencv4nodejs-prebuilt-install
Advanced tools
Asynchronous OpenCV 4.x nodejs bindings with JavaScript and TypeScript API.
Cross-platform!
npm i opencv4nodejs-prebuilt-install
check supporting platforms and processes!
const cv = require('opencv4nodejs-prebuilt-install');
import * as cv from 'opencv4nodejs-prebuilt-install'
Set your own properties inside of package.json for opencv4nodejs up to 4.6.0 depends on necessary versions and flags
"opencv4nodejs": {
"autoBuildWithoutContrib": 1,
"autoBuildOpencvVersion": "4.1.1",
"autoBuildFlags": "-DBUILD_opencv_world=1 -DBUILD_LIST=core,highgui,videoio -DOPENCV_FORCE_3RDPARTY_BUILD=ON -DBUILD_PNG=ON -DBUILD_TIFF=ON -DBUILD_JASPER=ON -DBUILD_JPEG=ON -DBUILD_ZLIB=ON -DBUILD_OPENEXR=ON -DWITH_FFMPEG=OFF -DWITH_GSTREAMER=ON -DBUILD_USE_SYMLINKS=OFF -DWITH_VTK=OFF",
"disableAutoBuild": 1
},
npm run create_opencvlib
Result in folder osOpencvWorlds/*/*.tar
npm run create_opencvnode_prebuild
Result in folder opencv/build/bin for windows or in opencv/build/lib for linux and darwin
Create fork of the repo and add necessary changes then create poll request to the repo and i will recreate libs
For example i was able to add method invert recently
Nan::SetMethod(target, "invert", Invert);
Nan::SetMethod(target, "invertAsync", InvertAsync);
NAN_METHOD(Core::Invert) {
FF::syncBinding<CoreBindings::Invert>("Core", "Invert", info);
}
NAN_METHOD(Core::InvertAsync) {
FF::asyncBinding<CoreBindings::Invert>("Core", "Invert", info);
}
static NAN_METHOD(Invert);
static NAN_METHOD(InvertAsync);
class Invert : public CvClassMethodBinding<Mat> {
public:
void createBinding(std::shared_ptr<FF::Value<cv::Mat>> self) {
auto flags = opt<FF::IntConverter>("flags", 0);
auto dst = ret<Mat::Converter>("dst");
executeBinding = [=]() {
cv::invert(self->ref(), dst->ref(), flags->ref());
};
};
};
export function invert(mat: Mat, flags?: number): Mat;
export function invertAsync(mat: Mat, flags?: number): Promise<Mat>;
FAQs
Asynchronous OpenCV 4.x nodejs bindings with JavaScript and TypeScript API.
The npm package opencv4nodejs-prebuilt-install receives a total of 987 weekly downloads. As such, opencv4nodejs-prebuilt-install popularity was classified as not popular.
We found that opencv4nodejs-prebuilt-install demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.