
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
@dydxprotocol/abacus
Advanced tools
Shared front-end and mobile logic written in [Kotlin Multiplatform](https://kotlinlang.org/docs/multiplatform.html).
Shared front-end and mobile logic written in Kotlin Multiplatform.
The library generates Swift framework for iOS, JVM library for Android, and JavaScript code for Web.
https://www.oracle.com/java/technologies/downloads/#java11
Abacus uses Cocoapods to integrate with iOS project. The gradle configuration contains the steps needed to generate the .podspec file. Run
./gradlew podspec
to generate abacus.podspec. Configure your iOS project (https://github.com/dydxprotocol/native-ios) to import abacus.podspec.
You can also build the Abacus for iOS by running:
./gradlew assembleXCFramework
This generates the iOS framework in build/XCFrameworks
folder.
Debugging on iOS directly from XCode is possible with a plugin (https://github.com/touchlab/xcode-kotlin)
Abacus builds and pushes the JVM target to MavenLocal repo with the followinng command:
./gradlew publishToMavenLocal
The Android app (https://github.com/dydxprotocol/native-android) has the Gradle build step to pull the Abacus target from MavenLocal.
Abacus generates Javascript and Typescript files with the following command:
./gradlew assembleJsPackage
This outputs into build/distributions
, and references the packages in the build/js
directory.
Sample integration from a html page can be find in integration/Web
.
Abacus publishes using a library (https://github.com/mpetuska/npm-publish) with the following steps.
./gradlew assembleJsPackage
./gradlew packJsPackage
./gradlew publishJsPackageToNpmjsRegistry
Shared code should have unit tests written in Kotlin residing in the src/CommonTest
directory. Run the tests with the following command
./gradlew test
Integration tests can be written to call Abacus from non-Kotlin code (i.e., Swift, JS). Sample integration projects can be found in the integration
directory.
// create a state machine
val stateMachine = PerpTradingStateMachine()
// send socket payload to the state machine and get the state
// the param is the complete socket text
val state = stateMachine.socket(payloadText)
// See src/commonTest/kotlin/exchange.dydx.abacus/PerpV3Tests.kt for testing code
Misc:
utils
protocols
state
(top state)
app
→ AppStateMachine
(contains network logic)modal
→ StateMachine
(contains business logic)changes
→ Changes
(utilities to identify which part of the state has changed)processing:
step 1: processor
(dynamic objects - dictionaries, list, not typed)
markets
orderbook
trades
funding
asset
(referenced from markets, such as icon, url etc)wallet
(user info)
account
subaccount
assetPositions
openPositions
orders
fills
transfers
historicalPnl
configs
(from Veronica mostly)step 2: calculator
(dynamic)
market
(summary info)account
(step 3)
subaccount
3.1 calculate position notionalTotal
/valueTotal
etc
3.2 calculate account equity etc, leverage``,
marginUsage,
buyingPower3.3 calculate position
leverage,
buyingPower`AccountTransformer
(step 2)
postOrder
and postAllOrderStates
for account (total from trade input) and positions (size from trade input)input
(step 1)
TradeInput
size
(size, usdcSize, leverage)TransferInput
(not complete)step 3: validator
(from postOrder
and postAllOrders
states)
trade
transfer
step 4: output
(structs, typed data)
step 5: responses
## `commontest`
* `test` (supporting classes, mostly mocks)
* `utils` (just utilities)
* `AppStateMachine` (app)
* `StateMachine` (payload and validation folder)
* `payload` (test `StateMachine` payload and interaction)
* `API` -> expected state
* `validation` (separated from payload, to target validation tests)
* `app` (test `AppStateMachine` IO requests)
FAQs
Shared front-end and mobile logic written in Kotlin Multiplatform (https://kotlinlang.org/docs/multiplatform.html).
The npm package @dydxprotocol/abacus receives a total of 0 weekly downloads. As such, @dydxprotocol/abacus popularity was classified as not popular.
We found that @dydxprotocol/abacus demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.