Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
go.riyazali.net/sqlite
sqlite
package provides a low-level interface that allows you to build sqlite
extensions that can be loaded dynamically at runtime
or linked statically at build-time (experimental)
This package can be installed with go get
as:
$ go get -u go.riyazali.net/sqlite
sqlite
is a cgo
package and requires a working c
compiler.
To build an sqlite
extension, you need to build your project with -buildmode=c-shared
. That would emit
a .so
file (or .dll
on windows), which you can then load into sqlite
.
Consider as an example, the sample upper
module in _examples/
. To build it, you'd use something similar to:
$ go build -buildmode=c-shared -o upper.so _examples/upper
which would emit an upper.so
in the current directory. Now, to use it with (say) the sqlite3
shell, you could do something like
$ sqlite3
> .load upper.so
> SELECT upper("sqlite3");
SQLITE3
> .exit
commit
/ rollback
hookscollation
scalar
, aggregate
and window
functionsvirtual table
does not support xShadowName
and nested transations yetEach of the support feature provides an exported interface that the user code must implement. Refer to code and godoc for more details.
MIT License Copyright (c) 2020 Riyaz Ali
Refer to LICENSE for full text.
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.