
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Scooch makes slideshows easy. You bring your own content and styling. It's super lightweight, around 1kb gzipped and easy to customise.
You can either download the repo, grab the JS and CSS and link them in your HTML, or if you prefer, you can install via NPM:
npm install scoochjs --save
See demo in index.html
for a setup guide.
You can pass an optional object to set any of the below items, as the second parameter, when instantiating Scooch.
e.g.
new Scooch(element, { autoplay: false });
Key | Description | Default Value |
---|---|---|
autoplay | Move to the next slide automatically | false |
autoplayInterval | How often (in MS) to change slide, if autoplay is true | 5000 |
keyboardControls | Enable keyboard controls | true |
enableFullscreen | Allow the slideshow to be made fullscreen | true |
Right arrow
, space
Left arrow
F
esc
💡 Tip: Hover over the left bottom corner of the index.html
demo page to see keyboard controls.
init
, onSlideChange
etc.)FAQs
A really lightweight, customisable vanilla Javascript carousel
The npm package scoochjs receives a total of 1 weekly downloads. As such, scoochjs popularity was classified as not popular.
We found that scoochjs demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.