Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
SpatialData is a data framework that comprises a FAIR storage format and a collection of python libraries for performant access, alignment, and processing of uni- and multi-modal spatial omics datasets. This repository contains the core spatialdata library. See the links below to learn more about other packages in the SpatialData ecosystem.
The spatialdata project uses a consensus based governance model and is fiscally sponsored by NumFOCUS. Consider making a tax-deductible donation to help the project pay for developer time, professional services, travel, workshops, and a variety of other needs.
The spatialdata project also received support by the Chan Zuckerberg Initiative.
Please refer to the documentation. In particular:
Another useful resource to get started is the source code of the spatialdata-io
package, which shows example of how to read data from common technologies.
Check out the docs for more complete installation instructions. To get started with the "batteries included" installation, you can install via pip:
pip install "spatialdata[extra]"
or via conda:
mamba install -c conda-forge spatialdata napari-spatialdata spatialdata-io spatialdata-plot
To get involved in the discussion, or if you need help to get started, you are welcome to use the following options.
scverse
Zulip (public or 1 to 1).Finally, especially relevant for for developers that are building a library upon spatialdata
, please follow this channel for:
Marconato, L., Palla, G., Yamauchi, K.A. et al. SpatialData: an open and universal data framework for spatial omics. Nat Methods (2024). https://doi.org/10.1038/s41592-024-02212-x
FAQs
Spatial data format.
We found that spatialdata demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.