Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
js.d3_cloud
This library packages the D3 Word Cloud Layout
_ for fanstatic
_.
.. _fanstatic
: http://fanstatic.org
.. _D3 Word Cloud Layout
: https://github.com/iLanguage/d3-cloud
This requires integration between your web framework and fanstatic
,
and making sure that the original resources (shipped in the resources
directory in js.d3_cloud
) are published to some URL. As a bonus, this
library also packages up a minified version of the original JavaScript.
The packaging is stored on GitHub at https://github.com/davidjb/js.d3_cloud. If you happen to come across a bug that corresponds to packaging, then please report it here. Pull requests are more than welcome if you're fixing something yourself -- the more help the better!
Any other bugs that relate to the library itself should be directed to the original developers.
This process requires installation of the package for development - the
suggested method to do this is via the Buildout
within this package::
cd js.d3_cloud
python boostrap.py
./bin/buildout
For minification of resources to succeed, you require a Java installation as
this process uses the YUI Compressor library (via the minify
andyuicompressor
Python packages).
In order to obtain a newer version of this library, do the following::
pushd js/d3_cloud/resources
wget https://github.com/iLanguage/d3-cloud/raw/master/src/d3.layout.cloud.js -O d3.layout.cloud.js
wget https://github.com/iLanguage/d3-cloud/raw/master/LICENSE -O LICENSE
popd
#Edit changelog, setup.py for versions, etc
python setup.py minify_d3_cloud
git commit -a -m "Updated for release 1.0.1"
git push
If you're doing this out in your own fork of the GitHub repository, then send through a pull request so everyone can benefit.
You can import d3_cloud
from js.d3_cloud
and need
it where you want
these resources to be included on a page::
from js.d3_cloud import d3_cloud d3_cloud.need()
CHANGES
FAQs
Fanstatic packaging of D3 Word Cloud Layout
We found that js.d3_cloud demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.