Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
com.loopj.android:android-async-http
Advanced tools
Since there were no active maintainers for this project for a long time, and issues got stale, security issues pile up and it's not viable to maintain this project further, given there are quality replacements, this project is closing down.
This library has many issues handling modern TLS/SSL security protocols using and problems with validating chain-of-trust of remote services, it communicates with. It also suffers from high-memory-usage issues, when handling large upstream or downstream jobs.
It is not suitable for modern projects, and thus, unless someone takes over the maintenance and invests big time into making it performance and secure again, it is not recommended to use the library further.
For issues with using this library or migrating to different one, use appropriate forum, for example https://stackoverflow.com/questions/tagged/android-async-http
or don't, i'm not a cop
An asynchronous, callback-based Http client for Android built on top of Apache's HttpClient libraries.
See what is new in version 1.4.11 released on 29th June 2020
https://github.com/android-async-http/android-async-http/blob/1.4.11/CHANGELOG.md
Latest Javadoc for 1.4.11 release are available here (also included in Maven repository):
https://android-async-http.github.io/android-async-http/doc/
For inspiration and testing on device we've provided Sample Application.
See individual samples here on Github
To run Sample application, simply clone the repository and run this command, to install it on connected device
gradle :sample:installDebug
You can now integrate this library in your project via Maven. There are available two kind of builds.
releases, maven central
https://repo1.maven.org/maven2/com/loopj/android/android-async-http/
Maven URL: https://repo1.maven.org/maven2/
GroupId: com.loopj.android
ArtifactId: android-async-http
Version: 1.4.11
Packaging: JAR or AAR
Gradle
repositories {
mavenCentral()
}
dependencies {
implementation 'com.loopj.android:android-async-http:1.4.11'
}
development snapshots snapshot might not be published yet
https://oss.sonatype.org/content/repositories/snapshots/com/loopj/android/android-async-http/
Maven URL: https://oss.sonatype.org/content/repositories/snapshots/
GroupId: com.loopj.android
ArtifactId: android-async-http
Version: 1.4.12-SNAPSHOT
Packaging: JAR or AAR
Gradle
repositories {
maven {
url 'https://oss.sonatype.org/content/repositories/snapshots/'
}
}
dependencies {
implementation 'com.loopj.android:android-async-http:1.4.11-SNAPSHOT'
}
Full details and documentation can be found on the project page here:
FAQs
Unknown package
We found that com.loopj.android:android-async-http demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.