
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Small library to create tags by typing
The usage is simple:
Create container element where taggify will be installed, like:
<div class="taggify"></div>
Include Taggify library script to your HTML code:
<script src="taggify.min.js"></script>
Then start using in your JS script:
<script>
(function () {
'use strict';
new window.Taggify();
})();
</script>
Taggify library uses a configuration object containing following properties:
Container selector to find HTML node to initialize taggify element. By default: '.taggify'
Indicator whether to use autocomplete callback. By default: false
The autocomplete callback. It takes 2 params:
The input event callback delay. After this time, the tags are created.
It's used to increase performance of the solution. By default: 100
The text to display to a user as a label. By default: 'Start typing ...'
Indicator whether to allow duplicated tags. Used when autocomplete is turned off.
By default: false
List of hot keys which generate tags when autocomplete is off.
The list contains key codes, like - coma is 188, but enter is 13.
By default: [13, 188]
FAQs
Create tags by typing
The npm package taggify receives a total of 0 weekly downloads. As such, taggify popularity was classified as not popular.
We found that taggify demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.