
Security News
npm Adopts OIDC for Trusted Publishing in CI/CD Workflows
npm now supports Trusted Publishing with OIDC, enabling secure package publishing directly from CI/CD workflows without relying on long-lived tokens.
github.com/fullstorydev/grpchan
This repo provides an abstraction for an RPC connection: the Channel
.
Implementations of Channel
can provide alternate transports -- different
from the standard HTTP/2-based transport provided by the google.golang.org/grpc
package.
This can be useful for providing new transports, such as HTTP 1.1, web sockets, or (significantly) in-process channels for testing.
This repo also contains two such alternate transports: an HTTP 1.1 implementation of gRPC (which supports all stream kinds other than full-duplex bidi streams) and an in-process transport (which allows a process to dispatch handlers implemented in the same program without needing serialize and de-serialize messages over the loopback network interface).
In order to use channels with your proto-defined gRPC services, you need to use a
protoc plugin included in this repo: protoc-gen-grpchan
.
go install github.com/fullstorydev/grpchan/cmd/protoc-gen-grpchan
You use the plugin via a --grpchan_out
parameter to protoc. Specify the same
output directory to this parameter as you supply to --go_out
. The plugin will
then generate *.pb.grpchan.go
files, alongside the *.pb.go
files. These
additional files contain additional methods that let you use the proto-defined
service methods with alternate transports.
//go:generate protoc --go_out=plugins=grpc:. --grpchan_out=. my.proto
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
npm now supports Trusted Publishing with OIDC, enabling secure package publishing directly from CI/CD workflows without relying on long-lived tokens.
Research
/Security News
A RubyGems malware campaign used 60 malicious packages posing as automation tools to steal credentials from social media and marketing tool users.
Security News
The CNA Scorecard ranks CVE issuers by data completeness, revealing major gaps in patch info and software identifiers across thousands of vulnerabilities.