
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
react-canvas-treemap
Advanced tools
Canvas based Treemap data visualization using React.
This package is part of Harvard Growth Lab’s portfolio of software packages, digital products and interactive data visualizations. To browse our entire portfolio, please visit The Viz Hub at growthlab.app. To learn more about our research, please visit Harvard Growth Lab’s home page.
npm install --save react-canvas-treemap
import React from 'react'
import TreeMap, {transformData} from 'react-canvas-treemap';
const App = () => {
...
const data = transformData({
data: fetchedData,
width: 500,
height: 500,
colorMap: colorMap,
});
return (
<TreeMap
highlighted={undefined}
cells={data.treeMapCells}
numCellsTier={0}
chartContainerWidth={500}
chartContainerHeight={500}
onCellClick={id => console.log(id)}
onMouseOverCell={id => console.log(id)}
onMouseLeaveChart={() => {}}
/>
)
}
export default App
The TreeMap component takes the following props:
string | undefined
ITreeMapCell[]
boolean
string
NumCellsTier
number
number
(id: string) => void
(id: string) => void
() => void
MIT © The President and Fellows of Harvard College
:warning: License: While this package has a MIT license, it uses Greensock, which is not an Open-Source software. All of the Greensock Code used here falls within their "No Charge" License. If you intend to use this package, make sure to familiarize yourself with the Greensock "No Charge" License.
FAQs
Canvas based Treemap data visualization using React.
The npm package react-canvas-treemap receives a total of 16 weekly downloads. As such, react-canvas-treemap popularity was classified as not popular.
We found that react-canvas-treemap demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.