Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@deploydao/migrator
Advanced tools
A program for deploying and upgrading programs.
The Migrator:
There are two forms of intended usage: "self-hosted" and the DeployDAO.
This may be used for development or if you want to maintain full control over your own smart contract deployment.
solana program write-buffer
. Ideally this bytecode is generated in a verifiable manner.note: this is subject to change
The DeployDAO is a decentralized autonomous organization that elects multisig holders to approve program upgrades and deploys.
To deploy a program, one should:
solana program write-buffer
. Ideally this bytecode is generated in a verifiable manner.Upgrading is done very similarly.
The DeployDAO program and SDK is distributed under the GPL v3.0 license.
FAQs
Migration management for Solana programs.
We found that @deploydao/migrator demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.