Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
github.com/ablegao/orm
##About
一个数据库ORM.
Please go to http://github.com/server-nado/orm !
代码已经转移到 http://github.com/server-nado/orm !
go get github.com/server-nado/orm
sqlite3 "github.com/mattn/go-sqlite3" mysql "github.com/go-sql-driver/mysql" postgree "github.com/lib/pq"
##数据库Model 建立方法
//引用模块
import "github.com/ablegao/orm"
//mysql 驱动
import _ "github.com/go-sql-driver/mysql"
//建立连接
// 参数分别为 名称 , 驱动, 连接字符串
// 注:必须包含一个default 连接, 作为默认连接。
orm.NewDatabase("default" , "mysql" , "user:passwd@ip/database?charset=utf8&parseTime=true")
//建立一个数据模型。
type UserInfo struct**** {
orm.Object
Id int64 `field:"id" auto:"true" index:"pk"`
Name string `field:"username"`
Passwd string `field:"password"`
}
##新增 CacheModel 模型, 支持分布式redis作为数据库缓存。
import "github.com/ablegao/orm"
import _ "github.com/go-sql-driver/mysql"
type userB struct {
CacheModule
Uid int64 `field:"Id" index:"pk" cache:"user" `
Alias string `field:"Alias"`
Money int64 `field:"money" `
}
func main(){
orm.CacheConsistent.Add("127.0.0.1:6379") //添加多个redis服务器
orm.SetCachePrefix("nado") //默认nado . 将作为redis key 的前缀
NewDatabase("default", "mysql", "happy:passwd@tcp(127.0.0.1:3306)/mydatabase?charset=utf8&parseTime=true")
b := new(userB)
b.Uid = 10000
err:=b.Objects(b).One()
if err!= nil {
panic(err)
}
fmt.Println(b.Uid ,b.Alias ,b.Money)
b.Incrby("Money" , 100)
fmt.Println(b.Money)
b.Save() //不执行不会保存到数据库 只会修改redis数据。
}
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.