
Security News
Package Maintainers Call for Improvements to GitHub’s New npm Security Plan
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
@expandorg/expand-vault
Advanced tools
The Expand Vault holds XPN tokens deposited by either workers or requesters, that are then withdrawable. This repo contains the ExpandVault contract and convenience wrappers for executing views and transactions.
There are three possible environments, each with their own .env
file and set using NODE_ENV
. For example:
NODE_ENV=ropsten npm run migrate --network ropsten
NODE_ENV=ropsten node scripts/foobar.js
NODE_ENV=production npm run migrate --network live
NODE_ENV=production node scripts/foobar.js
Add scripts to the scripts/
directory, using scripts/template.js
as a guide:
const runScript = require('../src/runScript');
runScript(async (vault, ownerAddress, web3) => {
// Script here
})
.then(() => console.log('done'))
.catch(err => console.error(err));
The vault
instance that's passed to your script has the following async
methods derived from the contract:
View methods return the relevant values.
addressOfUser(userId)
addressOfJob(jobId)
balanceOfUser(userId)
balanceOfJob(jobId)
Transactions return logged events on success, and throw errors on failure.
setUserAddress(userId, address)
setJobAddress(userId, address)
depositToUser(userId, value)
depositToJob(jobId, value)
withdrawUserDeposit(userId, value)
withdrawJobDeposit(jobId, value)
payoutFromJob(jobId, userId, value)
reclaimFromUser(userId, value)
reclaimFromJob(jobId, value)
FAQs
Convenience wrapper for the Expand vault Ethereum contract
We found that @expandorg/expand-vault demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
Product
Socket Firewall is a free tool that blocks malicious packages at install time, giving developers proactive protection against rising supply chain attacks.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.