
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
@condenast/cross-check-dsl
Advanced tools
A low-level validation library. Built on top of @condenast/cross-check. Detailed philosophy about cross-check can be found in @condenast/cross-check
.
It was originally extracted from Condé Nast's CMS and sponsored by Condé Nast.
It's largely focused on building a small, flexible, but useful core primitive for composing validations. This library focuses on ensuring that validators can be composed easily in various useful ways. The composition goals were informed by Condé Nast's working system, since the first iteration of this library successfully replaced existing validators in its production system.
The short version of the philosophy of cross-check:
The @condenast/cross-check
repository unpacks these points in much greater detail.
npm install
npm test
cross-check was originally extracted from Condé Nast's CMS, and the work to extract it and release it as open source was funded by Condé Nast.
FAQs
A DSL for building validations.
The npm package @condenast/cross-check-dsl receives a total of 171 weekly downloads. As such, @condenast/cross-check-dsl popularity was classified as not popular.
We found that @condenast/cross-check-dsl demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 354 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.