Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
@covalenthq/goldrush-kit
Advanced tools
Beautifully designed React components for web3 dApp frontend. Easily fetch data from 200+ blockchains. Open-source. Customizable.
Install goldrush-kit
using npm
:
npm install @covalenthq/goldrush-kit
or yarn
:
yarn add @covalenthq/goldrush-kit
GoldRushProvider
import { GoldRushProvider } from "@covalenthq/goldrush-kit";
GoldRushProvider
around the application.apikey
props with your Covalent API key. You can register for a free key on Covalent's website.<GoldRushProvider apikey="<YOUR_API_KEY>">{children}</GoldRushProvider>
import "@covalenthq/goldrush-kit/styles.css";
next.js
versions ^13.0
and are using app
router, make sure you have use client;
at the top of the file to disable Next's server component modules. Visit GoldRush's component documentation for more information.import {
GoldRushProvider,
NFTWalletTokenListView,
TokenBalancesListView,
TokenTransfersListView,
AddressActivityListView,
} from "@covalenthq/goldrush-kit";
Here's a full example to get you started. If you're using next.js
versions ^13.0
and are using app
router, make sure you have use client;
at the top of the file to disable Next's server component modules.
Note: You should always keep your API key private, never put it directly into your code, especially front end code. Instead, use an environment variable to inject the key into your code.
Be sure to secure your key to prevent unauthorized use in the Covalent platform by restricting usage to specific URLs.
"use client";
import "@covalenthq/goldrush-kit/styles.css";
import {
GoldRushProvider,
NFTWalletTokenListView,
TokenBalancesListView,
TokenTransfersListView,
AddressActivityListView,
} from "@covalenthq/goldrush-kit";
export default function GoldRushExample() {
return (
<main className="">
<GoldRushProvider
apikey={process.env.NEXT_PUBLIC_API_KEY}
mode="dark"
color="emerald"
>
<TokenBalancesListView
chain_names={[
"eth-mainnet",
"matic-mainnet",
"bsc-mainnet",
"avalanche-mainnet",
"optimism-mainnet",
]}
hide_small_balances
address="0xfc43f5f9dd45258b3aff31bdbe6561d97e8b71de"
/>
<TokenTransfersListView
chain_name="eth-mainnet"
address="0xfc43f5f9dd45258b3aff31bdbe6561d97e8b71de"
contract_address="0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48"
/>
<AddressActivityListView address="0xfc43f5f9dd45258b3aff31bdbe6561d97e8b71de" />
<NFTWalletTokenListView
address="0xfc43f5f9dd45258b3aff31bdbe6561d97e8b71de"
chain_names={[
"eth-mainnet",
"matic-mainnet",
"bsc-mainnet",
"avalanche-mainnet",
"optimism-mainnet",
]}
/>
</GoldRushProvider>
</main>
);
}
Template | Description | Link |
---|---|---|
Wallet & Portfolio UI | Display your tokens and NFTs across multiple chains. | https://github.com/covalenthq/goldrush-wallet-portfolio-ui |
NFT Collection Gallery & Analytics UI | Display NFTs by collection and see their details. | https://github.com/covalenthq/goldrush-nft-gallery-ui |
Uniswap-like Analytics UI | Display Uniswap-like analytics for the dex of your choice. | https://github.com/covalenthq/goldrush-uniswap-dex-dashboard |
Transaction Receipt View | A beautifully designed view for blockchain transactions. | https://github.com/covalenthq/goldrush-tx-receipt-ui |
Designed to transform cluttered blockchain transaction data into meaningful summaries useful to the user. Receipts are fully extensible and enhance the clarity and understanding of various blockchain activities. Imagine a transaction view that shows Game-Fi quest achievements, swap pool position data, or even staking impact on network security—this is all possible with GoldRush-Kit.
https://goldrush-tx-receipt-ui.vercel.app/
https://github.com/covalenthq/goldrush-tx-receipt-ui
Decode transaction log events to display them in a human-readable format. Useful for understanding the data that is emitted from smart contracts and is a critical component of any dApp. Works in tandem with GoldRush-Kit to provide a seamless experience for developers and users alike.
https://github.com/covalenthq/goldrush-decoder
The components used above are built React, Tailwind, and TypeScript. You can preview and customize the components using Storybook.
Storybook provides developers with a way to quickly prototype and develop components in isolation, while React provides the tools to quickly build out a web application. Tailwind provides a library of pre-built UI components and utility classes, while TypeScript adds type safety and autocompletion to the development process. Together, these tools provide developers with the tools they need to quickly and easily build complex, modern web applications.
Create and add a .env
file to the root directory of your project and the following to the file.
STORYBOOK_COVALENT_API_KEY = "<YOUR_API_KEY>"
npm run dev
npm run build:library
npm run build:storybook
Contributions, issues and feature requests are welcome! Feel free to check issues page.
Give a ⭐️ if this project helped you!
This project is Apache 2.0 licensed.
0.5.6
Features
LatestTransactions
for a chainFixes
CardDetail
for all heading-value based data pairsTableList
for all the tablesTableList
to improve visual similarityFAQs
Beautifully designed React components for web3 dApp frontend. Easily fetch data from 200+ blockchains. Open-source. Customizable.
The npm package @covalenthq/goldrush-kit receives a total of 6 weekly downloads. As such, @covalenthq/goldrush-kit popularity was classified as not popular.
We found that @covalenthq/goldrush-kit demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.