Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
@ephox/katamari
Advanced tools
katamari
is a collection of various data structures and reusable higher-order functions. It does not bundle any commands. It is only a collection of bolt
(github, npm) modules.
katamari
is available as an npm
package. You can install it via the npm package @ephox/katamari
npm install @ephox/katamari
.
Note, refrain from using any modules that are not in the
api
package.
Below is a list of commonly used parts of katamari
Option
: A representation of None or Some(x)
Result
: A representation of Error(str) or Value(v)
Future
: An abstraction over an asynchronous value
FutureResult
: A composition of a Result
and a Future
LazyValue
: An asynchronous value that is only calculated once
Cell
: A mutable piece of data'
Singleton
: A mutable piece of optional data
Struct
: An immmutable collection of fields
Adt
: An approximate representation of an Algebraic Data Type in JavaScript. It is based on the Church Encoding method.
Arr
: collection of functions that operate on arrays
Obj
: collection of functions that operate on JavaScript objects
Merger
: collection of functions to merge JavaScript objects
katamari
uses bolt
to run atomic tests. The tests are chiefly written using jsverify
$ npm test
FAQs
Basic data type library
The npm package @ephox/katamari receives a total of 2,160 weekly downloads. As such, @ephox/katamari popularity was classified as popular.
We found that @ephox/katamari demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.