
Research
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
rehype-picture
Advanced tools
rehype plugin to wrap images in pictures.
This package is a unified (rehype) plugin to change images (<img>)
into pictures (<picture>).
This lets you use a single image source in your content which is then
automatically turned into a picture with several sources.
unified is a project that transforms content with abstract syntax trees (ASTs). rehype adds support for HTML to unified. hast is the HTML AST that rehype uses. This is a rehype plugin that changes images in the tree.
This plugin is useful when you have the same images in different file formats.
For example, when you have a build step that generates alternative image files
(say, .webps) from source files (say, .jpgs).
Then, when you link to the source images, you can use this plugin to generate
the markup for both.
This package is ESM only. In Node.js (version 16+), install with npm:
npm install rehype-picture
In Deno with esm.sh:
import rehypePicture from 'https://esm.sh/rehype-picture@5'
In browsers with esm.sh:
<script type="module">
import rehypePicture from 'https://esm.sh/rehype-picture@5?bundle'
</script>
import rehypeParse from 'rehype-parse'
import rehypePicture from 'rehype-picture'
import rehypeStringify from 'rehype-stringify'
import {unified} from 'unified'
const file = await unified()
.use(rehypeParse, {fragment: true})
.use(rehypePicture, {
jpg: {webp: 'image/webp'},
png: {svg: 'image/svg+xml'}
})
.use(rehypeStringify)
.process('<img src="cat.jpg">\n<img src="logo.png">')
console.log(String(file))
Yields:
<picture><source srcset="cat.webp" type="image/webp"><img src="cat.jpg"></picture>
<picture><source srcset="logo.svg" type="image/svg+xml"><img src="logo.png"></picture>
This package exports no identifiers.
The default export is rehypePicture.
unified().use(rehypePicture[, options])Wrap images in pictures.
options (Options, optional)
— configurationTransform (Transformer).
OptionsConfiguration (TypeScript type)
Maps file extensions (without dot, so such as jpg) to sources.
type Options = Record<string, Sources | null | undefined>
SourcesSources (TypeScript type)
Maps file extensions (without dot, so such as webp) to mime types.
type Sources = Record<string, string | null | undefined>
This package is fully typed with TypeScript.
It exports the additional types Options and
Sources.
Projects maintained by the unified collective are compatible with maintained versions of Node.js.
When we cut a new major release, we drop support for unmaintained versions of
Node.
This means we try to keep the current release line, rehype-picture@^5,
compatible with Node.js 16.
This plugin works with rehype-parse version 3+, rehype-stringify version 3+,
rehype version 4+, and unified version 6+.
Although this plugin should be safe to use, be careful with user input images as it’s often possible to hide JavaScript inside them (such as GIFs, WebPs, and SVGs). User provided images open you up to a cross-site scripting (XSS) attack.
See contributing.md in rehypejs/.github for ways
to get started.
See support.md for ways to get help.
This project has a code of conduct. By interacting with this repository, organization, or community you agree to abide by its terms.
FAQs
rehype plugin to wrap images in pictures
The npm package rehype-picture receives a total of 53 weekly downloads. As such, rehype-picture popularity was classified as not popular.
We found that rehype-picture demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.

Security News
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.