data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
A way to use the awesome Agile Toolkit Icon Set within your project.
From the command line:
sudo gem install atk_icons
Installing into an existing Rails project:
# add atk_icons to your Gemfile
gem 'atk_icons'
# require atk_icons from your Compass configuration file (compass.rb)
require 'atk_icons'
# import the extension into your scss/sass file
@import atk_icons
# copy atk_icons.png to your public/images directory
cd public/images && curl http://bit.ly/iHd2XF
Or create a new project:
compass create <project_name> -r atk_icons --using atk_icons
#import the extension into your scss/sass file
@import "atk_icons"
# for a list of all the icons available, see http://www.agiletech.ie/blog/128x16x16
.button.delete
/* this will add an :after pseudo-selector with the specified icon
@include atk-icon-pseudo("basic-ex")
.button.add span.icon
/* you can also set the icon to a sub-element
@include atk-icon("basic-plus")
The previous SASS will result in the following CSS:
.button.delete {
position: relative;
padding-left: 15px;
}
.button.delete:before {
background-image: url('/images/atk_icons.png');
display: inline-block;
height: 16px;
width: 14px;
background-position: -2px -64px;
content: "";
position: absolute;
left: 0px;
top: 0px;
}
.button.add span.icon {
background-image: url('/images/atk_icons.png');
display: inline-block;
height: 16px;
width: 14px;
background-position: -2px 0px;
}
Copyright (c) 2011 Stefano Verna. See LICENSE.txt for further details.
FAQs
Unknown package
We found that atk_icons demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.