Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
.. image:: https://travis-ci.com/mapbox/mercantile.svg :target: https://travis-ci.com/mapbox/mercantile :alt: Build Status
.. image:: https://coveralls.io/repos/github/mapbox/mercantile/badge.svg?branch=master :target: https://coveralls.io/github/mapbox/mercantile?branch=master :alt: Coverage Status
.. image:: https://readthedocs.org/projects/mercantile/badge/?version=latest :target: http://mercantile.readthedocs.io/en/latest/?badge=latest :alt: Documentation Status
Spherical mercator coordinate and tile utilities
Documentation: http://mercantile.readthedocs.io/en/latest/
The mercantile module provides ul(xtile, ytile, zoom)
and bounds(xtile, ytile, zoom)
functions that respectively return the upper left corner and
bounding longitudes and latitudes for XYZ tiles, a xy(lng, lat)
function
that returns spherical mercator x and y coordinates, a tile(lng, lat, zoom)
function that returns the tile containing a given point, and
quadkey conversion functions quadkey(xtile, ytile, zoom)
and
quadkey_to_tile(quadkey)
for translating between quadkey and tile
coordinates.
.. code-block:: pycon
>>> import mercantile
>>> mercantile.ul(486, 332, 10)
LngLat(lng=-9.140625, lat=53.33087298301705)
>>> mercantile.bounds(486, 332, 10)
LngLatBbox(west=-9.140625, south=53.12040528310657, east=-8.7890625, north=53.33087298301705)
>>> mercantile.xy(*mercantile.ul(486, 332, 10))
(-1017529.7205322663, 7044436.526761846)
>> mercantile.xy_bounds(486, 332, 10)
Bbox(left=-1017529.7205322663, bottom=7005300.768279833, right=-978393.962050256, top=7044436.526761846)
>>> mercantile.tile(*mercantile.ul(486, 332, 10) + (10,))
Tile(x=486, y=332, z=10)
>>> mercantile.quadkey(486, 332, 10)
'0313102310'
>>> mercantile.quadkey_to_tile('0313102310')
Tile(x=486, y=332, z=10)
Also in mercantile are functions to traverse the tile stack.
.. code-block:: pycon
>>> mercantile.parent(486, 332, 10)
Tile(x=243, y=166, z=9)
>>> mercantile.children(mercantile.parent(486, 332, 10))
[Tile(x=486, y=332, z=10), Tile(x=487, y=332, z=10), Tile(x=487, y=333, z=10), Tile(x=486, y=333, z=10)]
Named tuples are used to represent tiles, coordinates, and bounding boxes.
Mercantile's command line interface, named "mercantile", has commands for getting the shapes of Web Mercator tiles as GeoJSON and getting the tiles that intersect with a GeoJSON bounding box.
.. code-block:: console
$ mercantile --help
Usage: mercantile [OPTIONS] COMMAND [ARGS]...
Command line interface for the Mercantile Python package.
Options:
-v, --verbose Increase verbosity.
-q, --quiet Decrease verbosity.
--version Show the version and exit.
--help Show this message and exit.
Commands:
bounding-tile Print the bounding tile of a lng/lat point, bounding box, or
GeoJSON objects.
children Print the children of the tile.
neighbors Print the neighbors of the tile.
parent Print the parent tile.
quadkey Convert to/from quadkeys.
shapes Print the shapes of tiles as GeoJSON.
tiles Print tiles that overlap or contain a lng/lat point, bounding
box, or GeoJSON objects.
supermercado <https://github.com/mapbox/supermercado>
__ is another python lib
with added tile logic functionality (union tile shapes, find edge tiles, and
find tile intersections for complex geometries).
node-sphericalmercator <https://github.com/mapbox/node-sphericalmercator>
__
provides many of the same features for Node.
tilebelt <https://github.com/mapbox/tilebelt>
__ has some of the GeoJSON
features as mercantile and a few more (tile parents, quadkey).
morecantile <https://github.com/developmentseed/morecantile>
__ is like mercantile,
but with support for other TileMatrixSet grids.
FAQs
Web mercator XYZ tile utilities
We found that mercantile demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.