Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
github.com/rthornton128/goncurses
Goncurses is an ncurses library for the Go programming language. It requires both pkg-config and ncurses C development files be installed.
The go tool is the recommended method of installing goncurses. Issue the following command on the command line:
$ go get github.com/rthornton128/goncurses
The ncurses C development library must be installed on your system in order to build and install Goncurses. For example, on Debian based systems you can run:
$ sudo apt install libncurses-dev
OSX and Windows users should visit the Wiki for installation instructions.
Cgo will fail to build with an invalid or unknown flag error with recent versions of ncurses. Unfortunately, the cgo tool only provides one mechanism for overcoming this. You need to set *_ALLOW environment variables to overcome the issue. There are no cgo directives or any other clever ways (that I know of) to fix this.
This package provides a Makefile as one solution. Another would be to set the variables in your shell in whatever way makes you feel comfortable.
No functions which operate only on stdscr have been implemented because it makes little sense to do so in a Go implementation. Stdscr is treated the same as any other window.
Whenever possible, versions of ncurses functions which could potentially have a buffer overflow, like the getstr() family of functions, have not been implemented. Instead, only mvwgetnstr() and wgetnstr() are used.
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.