Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Aseprite is a wonderful pixelart tool. Unfortunately its license is not OSI compliant, even if the source code is available. This makes it complicated to rely on the tool being available everywhere it's needed. This is a problem for CI servers or open-source application stores like F-Droid.
Asetools are open-source command-line tools to work with Aseprite images.
The asesplit
tool turns .ase images into .png. It can extract individual layers and/or slices, trim and rotate them.
usage: asesplit [-h] [--split-layers] [--split-slices] [--trim]
[--rotate ANGLE] [--dry-run]
ase_file format
Turn an Aseprite file into one or several png files.
positional arguments:
ase_file
format Define the name of the generated files. Supported keywords:
{title}, {layer}, {frame}, {slice}
options:
-h, --help show this help message and exit
--split-layers
--split-slices
--trim
--rotate ANGLE Rotate image by ANGLE degrees counter-clockwise
--dry-run
The aseinfo
tool gives you information about the content of a .ase file.
usage: aseinfo [-h] [-j] ase_file
Display info about an aseprite file
positional arguments:
ase_file
options:
-h, --help show this help message and exit
-j, --json JSON output
The recommended way to install is using pipx.
pipx install asetools
You can run tests using pytest
. Just run pytest
in this directory.
Asetools works well for me: it has been used for years now in Pixel Wheels, but its support for .ase files is limited to the subset of Aseprite features I use. In particular, it currently only supports sprites with a color palette.
FAQs
Tools to work with Aseprite files
We found that asetools demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.