Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
com.epam.deltix:SdmxStructureRetrieval
Advanced tools
A fork of a wonderful SdmxSource
library by Metadata Technology
.
The fork is based on latest (to date) public version of SdmxSource
1.5.6.6
. The motivation behind forking is to resolve several limitations of the original library that are important for its wider adoption as well as wider community contribution to the project.
Released on GitHub
. Previously the source code was only available as a -sources
artifact within a Maven
package. This provides a common playground for community contribution.
Published to Maven Central
. Previously only available from private Maven
registry owned by Metadata Technology
subject to downtimes.
Removed aggressive dependency injection and transitive dependencies to Spring
framework. Design of the original library was heavily using dependency injection mechanism. This design decision complicated using the library as a set of utility classes making integration with the library complex and invasive from the perspective of transitive dependencies to Spring
packages. Library code was refactored to enable manual creation and initialization of objects. While the objects are no longer 'beans', their original naming which used Beans
suffix was preserved.
SDMX-JSON
serialization / deserialization for structural artefacts. Ported from .NET version of SdmxSource
by Eurostat
.SDMX-CSV
serialization / deserialization for data sets.SdmxSource
by Eurostat
.FAQs
Open source reference implementation of SDMX
We found that com.epam.deltix:SdmxStructureRetrieval demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.