
Research
Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.
github.com/pytomtoto/tview
Advanced tools
This Go package provides commonly needed components for terminal based user interfaces.

Among these components are:
They come with lots of customization options and can be easily extended to fit your needs.
go get github.com/pytomtoto/tview
This basic example creates a box titled "Hello, World!" and displays it in your terminal:
package main
import (
"github.com/pytomtoto/tview"
)
func main() {
box := tview.NewBox().SetBorder(true).SetTitle("Hello, world!")
if err := tview.NewApplication().SetRoot(box, true).Run(); err != nil {
panic(err)
}
}
Check out the GitHub Wiki for more examples along with screenshots. Or try the examples in the "demos" subdirectory.
For a presentation highlighting this package, compile and run the program found in the "demos/presentation" subdirectory.
tviewtviewRefer to https://pkg.go.dev/github.com/pytomtoto/tview for the package's documentation. Also check out the Wiki.
This package is based on github.com/pytomtoto/tcell (and its dependencies) as well as on github.com/rivo/uniseg.
I try really hard to keep this project backwards compatible. Your software should not break when you upgrade tview. But this also means that some of its shortcomings that were present in the initial versions will remain. In addition, at least for the time being, you won't find any version tags in this repo. The newest version should be the one to upgrade to. It has all the bugfixes and latest features. Having said that, backwards compatibility may still break when:
tcell) changes in such a way that forces me to make changes in tview as well,Primitive. You shouldn't need these interfaces unless you're writing your own primitives for tview. (Yes, I realize these are public interfaces. This has advantages as well as disadvantages. For the time being, it is what it is.)Add your issue here on GitHub. Feel free to get in touch if you have any questions.
We follow Golang's Code of Conduct which you can find here.
FAQs
Unknown package
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.