Security News
The Risks of Misguided Research in Supply Chain Security
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.
github.com/go-sqlite/sqlite3
sqlite3
is a pure Go package decoding the SQLite
file format as
described by:
http://www.sqlite.org/fileformat.html
WIP: The near-term aim for sqlite3
is to iterate through the
data in tables in SQLite
files: ie., readonly access, and no actual
SQL queries.
It doesn't quite do that yet: so far it just parses the
sqlite_master
data enough to find a list of tables and their names.
$ go get github.com/go-sqlite/sqlite3
sqlite3
is released under the BSD-3
license.
package main
import (
"fmt"
"github.com/go-sqlite/sqlite3"
)
func main() {
db, err := sqlite3.Open("test.sqlite")
if err != nil {
panic(err)
}
defer db.Close()
for _, table := range db.Tables() {
fmt.Printf(">>> table=%#v\n", table)
}
}
We're always looking for new contributing finding bugs, fixing issues, or writing some docs. If you're interested in contriburing source code changes you'll just need to pull down the source code. You can run tests with go test ./...
in the root of this project.
Make sure to add yourself to AUTHORS
and CONTRIBUTORS
if you submit a PR. We want you to take credit for your work!
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.