
Security News
Nx npm Packages Compromised in Supply Chain Attack Weaponizing AI CLI Tools
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.
rome-rails wraps the Rome (GitHub] javascript library for use in a Ruby on Rails project.
Rome is a customizable date (and time) picker.
Rome depends on moment
,
which is bundled by default.
If you're already using moment
,
you can use a version of Rome that doesn't bundle moment
.
It doesn't depend on jQuery or other frameworks, though.
Add the following to your Gemfile
:
gem "rome-rails"
moment
)Rome rails includes a bundled version of moment.js
.
Add the following directive to your Javascript manifest file (application.js
):
//= require rome
moment
)If you're already using moment
,
(perhaps with the
momentjs-rails
gem?)
you can included a standalone version of Rome.
Just make sure you require moment
before rome-standalone
in your Javascript manifest file (application.js
).
//= require moment //= require rome.standalone
Add the following directive to your Stylesheets manifest file (application.css
):
//= require rome
If you're using sass-rails
, and your manifest file is application.**scss**
,
then you should use Sass's style @import
functions
@import "rome";
The version of this gem will match the version of the underlying Rome library.
After checking out the repo, run bundle
to install dependencies.
Then, run rake spec
to run the tests.
Bug reports, pull requests, support queries are welcome on GitHub at https://github.com/cllns/rome-rails. This project actively pursues maintaining a safe, welcoming space for collaboration, and contributors are expected to adhere to the Contributor Covenant code of conduct.
The gem is available as open source under the terms of the MIT License.
FAQs
Unknown package
We found that rome-rails demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.
Security News
CISA’s 2025 draft SBOM guidance adds new fields like hashes, licenses, and tool metadata to make software inventories more actionable.
Security News
A clarification on our recent research investigating 60 malicious Ruby gems.