
Security News
Google’s OSV Fix Just Added 500+ New Advisories — All Thanks to One Small Policy Change
A data handling bug in OSV.dev caused disputed CVEs to disappear from vulnerability feeds until a recent fix restored over 500 advisories.
@dfinity/didc
Advanced tools
A multi-purpose Candid tool for JavaScript projects, including encoding and decoding Candid values.
import { getServiceMethods, encode, decode } from "@dfinity/didc";
// The IDL in text format to be used, most canisters expose their IDL through
// the `candid:service` public metadata.
//
// You can fetch the IDL with an agent call or dfx with `dfx canister metadata <canisterId> candid:service`
export const IDL = `
type StoreNumberInput = record {
number : nat64;
};
type InitArgs = record {
name : text;
};
type SomeType = record {
field1 : text;
field2 : nat64;
};
service : (InitArgs) -> {
store_number : (input : StoreNumberInput) -> ();
get_number : () -> (nat64) query;
};
`;
// Gets the service methods from the IDL and returns an array of the methods.
//
// Example returned value: ['store_number', 'get_number']
const methods = getServiceMethods(IDL);
// Encodes a candid in text format to a hex representation.
//
// Example returned value: '4449444c016c01c98dea8b0a7801005a00000000000000'
const encoded = encode({
idl: IDL,
input: "(record { number=90; })",
withType: { kind: "methodParams", name: "store_number" },
targetFormat: "hex",
});
// Encodes a specific type - encode values according to a named type
const encoded = encode({
idl: IDL,
input: '(record { field1="Hello"; field2=42 })',
withType: { kind: "type", name: "SomeType" },
targetFormat: "hex",
});
// Encodes service constructor parameters
const encoded = encode({
idl: IDL,
input: '(record { name="MyCanister" })',
withType: { kind: "serviceParams" },
targetFormat: "hex",
});
// Decodes a hex representation of a candid value to a text format.
//
// Example returned value: '(90 : nat64)'
const decoded = decode({
idl: IDL,
input: "4449444c0001785a00000000000000",
serviceMethod: "get_number",
inputFormat: "hex",
targetFormat: "candid",
});
Returns a list of method names available in the service defined in the IDL.
Encodes Candid text format to hex or blob format.
Parameters:
idl
: The Candid IDL to encode againstinput
: The Candid text value to encodewithType
(optional): Type specifier for encoding (discriminated union):
{ kind: "methodParams", name: "method_name" }
: Uses the parameters of the specified method{ kind: "type", name: "type_name" }
: Uses the specified type{ kind: "serviceParams" }
: Uses the service constructor parameterstargetFormat
(optional): Output format, either 'hex' (default) or 'blob'Decodes hex or blob format to Candid text format.
Parameters:
idl
: The Candid IDL to decode againstinput
: The hex or blob value to decodeserviceMethod
(optional): Method to use for type informationuseServiceMethodReturnType
(optional): Whether to use return types (true) or parameter types (false)inputFormat
(optional): Input format, either 'hex' (default) or 'blob'targetFormat
(optional): Output format, only 'candid' is supported currentlyFAQs
Utility tools for candid.
We found that @dfinity/didc demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 12 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
A data handling bug in OSV.dev caused disputed CVEs to disappear from vulnerability feeds until a recent fix restored over 500 advisories.
Research
/Security News
175 malicious npm packages (26k+ downloads) used unpkg CDN to host redirect scripts for a credential-phishing campaign targeting 135+ organizations worldwide.
Security News
Python 3.14 adds template strings, deferred annotations, and subinterpreters, plus free-threaded mode, an experimental JIT, and Sigstore verification.