Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
prismic-dom
Advanced tools
🚨 Replaced by
@prismicio/helpers
📣
prismic-dom
is deprecated and replaced by@prismicio/helpers
v2. All functions fromprismic-dom
have been moved into the more general@prismicio/helpers
package. Moving forward, only security updates will be released toprismic-dom
.See the
@prismicio/helpers
v2 Migration Guide to learn how to upgrade your project.
It's meant to work in pair with the prismic-javascript library, a new javascript kit for the prismic API v2 available here:
Your endpoint must contains "v2" at the end, otherwise it means that you're working on the API V1 so this library won't work for you.
apiEndpoint: your-repo-name.prismic.io/api/v2
npm install prismic-dom --save
https://unpkg.com/prismic-dom
(You may need to adapt the version number)
On our release page: https://github.com/prismicio/prismic-dom/releases.
The kit is universal, it can be used:
You can find an integration of prismic content with the new API V2 in the following project:
With NodeJS, you can expose PrismicDOM directly in your locals to have it in your templates:
import PrismicDOM from 'prismic-dom';
res.locals.DOM = PrismicDOM;
Render a RichText:
DOM.RichText.asHtml(mydoc.data.myrichtext, linkResolver)
DOM.RichText.asText(mydoc.data.myrichtext)
Get a URL from a Link fragment of any kind
//link resolver not required if sure that it's not a document link
DOM.Link.url(mydoc.data.mylink, ctx.linkResolver)
Convert a Date as string from the API to an ISO Date:
DOM.Date(mydoc.data.mydate)
Source files are in the src/
directory. You only need Node.js and npm
to work on the codebase.
npm install
npm run dev
Please document any new feature or bugfix using the JSDoc syntax. You don't need to generate the documentation, we'll do that.
If you feel an existing area of code is lacking documentation, feel free to write it; but please do so on its own branch and pull-request.
If you find existing code that is not optimally documented and wish to make it better, we really appreciate it; but you should document it on its own branch and its own pull request.
This software is licensed under the Apache 2 license, quoted below.
Copyright 2013-2017 Prismic.io (http://prismic.io).
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this project except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0.
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
FAQs
Set of helpers to manage Prismic data
The npm package prismic-dom receives a total of 12,107 weekly downloads. As such, prismic-dom popularity was classified as popular.
We found that prismic-dom demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.