Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
@cryptovoxels/marketplace-js
Advanced tools
WORK IN PROGRESS
A package to allow anyone to interact with the Voxels marketplace contracts.
The contracts are based here The graph repo is based here
Clone repo get clone https://github.com/cryptovoxels/marketplace-js.git
npm i
to install the dependencies. If you encounter some issues, try LTS node v14.
Run npm run abi-type-gen
to generate the types of the contract given the ABIs.
Setup your environment
Create a branch and do your changes
Make sure your code is formatted using npm run format
Also make sure your code builds using npm run build
Make sure you add tests and that tests run smoothly with npm run test
(see test section below)
Create a Pull request at https://github.com/cryptovoxels/Voxels-Scripting-Server .
For testing, you need ganache
to run a local network.
Run npm i -g ganache
to install ganache globally. If you encounter issues, try the command again with a lower version of NodeJS; (LTS v14 works fine)
Run ganache by running the command ganache
in a separate console
Run npm run test
At the moment, npm run test
is setup to deploy the abis of test/abis/**.json
on the local network and then dynamically creates a .env
file.
It's not a great behavior especially if we need a sticky env
file in the future.
install with npm i @cryptovoxels/marketplace-js
Use
const provider = window.ethereum;
const marketplaceSDK = new VoxelsMarketplace(window.ethereum);
const myItemToList = {
token_id: 1;
address: '0x...';
price: 0.5;
quantity: 1;
}
await marketplace.list(myItemToList)
// emits events
FAQs
A simple JS sdk to interact with Voxels' marketplace
The npm package @cryptovoxels/marketplace-js receives a total of 5 weekly downloads. As such, @cryptovoxels/marketplace-js popularity was classified as not popular.
We found that @cryptovoxels/marketplace-js demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.