Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
markyp-based HTML implementations.
The project is listed on the Python Package Index, it can be installed simply by executing pip install markyp-html
.
If you are not familiar with the basic concepts of markyp
, please start by having a look at its documentation here.
The following very short example creates the most basic Hello World webpage. As you can see, all it takes is a single webpage()
call and string conversion.
from markyp_html import webpage
page = webpage("Hello World!", page_title="Hello World")
# Get the actual HTML markup.
html = str(page) # or page.markup
print(html)
Here is a slightly more sophisticated Hello World example, that contains all kinds of metadata, some CSS, and a couple of simple text elements:
from markyp_html import meta, style, webpage
from markyp_html.text import h1, p
from markyp_html.inline import strong
page = webpage(
h1("markyp-html"),
strong(p("Hello World!")),
p("This page was generated using Python and markyp-html."),
page_title="markyp-html demo page",
head_elements=[style("h1 {color:red;}\np {color:blue;}")],
metadata=[
meta.author("Website Author"),
meta.charset("UTF-8"),
meta.description("markyp-html demo"),
meta.keywords("markyp-html,markup,Python,HTML"),
meta.viewport("width=device-width, initial-scale=1.0")
]
)
# Get the actual HTML markup.
html = str(page) # or page.markup
print(html)
markyp-html
extensionsmarkyp-html
is built on markyp. In general, extensions follow the markyp-{domain-or-extension-name}
naming convention.
Here is a list of extensions built on top of markyp-html
:
markyp-bootstrap4
: Bootstrap 4 implementation at https://github.com/volfpeter/markyp-bootstrap4, contribution is welcome.markyp-fontawesome
: Font Awesome icons for markyp-html
-based web pages at https://github.com/volfpeter/markyp-fontawesome, contribution is welcome.markyp-highlightjs
: Code highlighting in HTML using highlight.js
at https://github.com/volfpeter/markyp-highlightjs, contribution is welcome.If you have created an open source markyp-html
extension, please let us know and we will include your project in this list.
In general, please treat each other with respect and follow the below guidelines to interact with the project:
[Question] <issue-title>
title.[Bug] <issue-title>
title, an adequate description of the bug, and a code snippet that reproduces the issue if possible.[Enhancement] <issue-title>
title and a clear description of the enhancement proposal.Every form of contribution is welcome, including documentation improvements, tests, bug fixes, and feature implementations.
Please follow these guidelines to contribute to the project:
mypy
is used to type-check the codebase, submitted code should not produce typing errors. See this page for more information on mypy
.#refs <issue-id>
to the end of commit messages).If you have any questions about contributing to the project, please contact the project owner.
As mentioned in the contribution guidelines, the project is type-checked using mypy
, so first of all, the project must pass mypy
's static code analysis.
The project is tested using pytest
. The chosen test layout is that tests are outside the application code, see this page for details on what it means in practice.
If pytest
is installed, the test set can be executed using the pytest test
command from within the project directory.
If pytest-cov
is also installed, a test coverage report can be generated by executing pytest test --cov markyp_html
from the root directory of the project.
The library is open-sourced under the conditions of the MIT license.
FAQs
HTML element implementations based on markyp.
We found that markyp-html demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.