
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@huma-shan/payment-detection
Advanced tools
@huma-shan/payment-detection is a typescript library part of the Request Network protocol.
It contains the implementation of request-related events interpretations, typically onchain payments of requests.
The interpretation of events is specified by the payment extension added to the request. Cf. advanced-logic specifications.
If a payment network has been given to the request, the payment detection can be done.
Based on information found in the payment network state, and included manual payment declarations, the library will perform queries and feed the property balance of the request with:
balance: the detected amount paid on the request, in request currencyevents: all the payments, payment declarations, refunds, and other balance-related events with the amount, timestamp etc...This library relies on two concepts:
InfoRetrievers, implementing the getTransferEvents() method (cf. IPaymentRetriever)getBalance(), which calls retrievers and interpret events according to the payment network (cf. Abstract PaymentDetectorBase). getBalance() returns the balance as well as events: payments, refunds, and possibly other events (declarations, escrow events...)A good part of the logic is implemented in the abstract class PaymentDetectorBase:
export abstract class PaymentDetectorBase<
TExtension extends ExtensionTypes.IExtension,
TPaymentEventParameters,
> implements PaymentTypes.IPaymentNetwork<TPaymentEventParameters>
{
public async getBalance(
request: RequestLogicTypes.IRequest,
): Promise<PaymentTypes.IBalanceWithEvents<TPaymentEventParameters>> {
// ...
// getEvents() should be implemented by children payment detectors, and use appropriate retrievers
// For example: RPC or The Graph based retriever
const rawEvents = await this.getEvents(request);
// ...
// computeBalance() sums up all payment events and deduces all refunds.
const balance = this.computeBalance(events).toString();
return {
balance,
events,
};
}
}
For TheGraph-based information retrieval, a client can be retrieved using getTheGraphClient() in ./src/thegraph/index.ts. It provides a strongly typed interface, generated based on the queries in /src/thegraph/queries.
The automated type generation is configured within files ./codegen.yml (for EVM chains) and ./codegen-near.yml (for Near) and output in ./src/thegraph/generated. It depends on the deployed subgraphes schema and on the queries.
The code generation is included in the pre-build script and can be run manually:
yarn codegen
FAQs
Payment detection using ethers.
The npm package @huma-shan/payment-detection receives a total of 15 weekly downloads. As such, @huma-shan/payment-detection popularity was classified as not popular.
We found that @huma-shan/payment-detection demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.