Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@ledhed2222/ripple-lib
Advanced tools
A TypeScript/JavaScript API for interacting with the XRP Ledger in Node.js and the browser
A JavaScript/TypeScript library for interacting with the XRP Ledger
This is the recommended library for integrating a JavaScript/TypeScript app with the XRP Ledger, especially if you intend to use advanced functionality such as IOUs, payment paths, the decentralized exchange, account settings, payment channels, escrows, multi-signing, and more.
See the full reference documentation on the XRP Ledger Dev Portal.
What is xrpl.js used for? The applications on the list linked above use xrpl.js
. Open a PR to add your app or project to the list!
rippled
server from Node.js or a web browseryarn
may work but we use package-lock.json
.See also: RippleAPI Beginners Guide
In an existing project (with package.json
), install xrpl.js
:
$ npm install xrpl@beta
Then see the documentation.
If you want to use xrpl.js
with React Native you will need to have some of the NodeJS modules available. To help with this you can use a module like rn-nodeify.
Install dependencies (you can use npm
as well):
npm install react-native-crypto
npm install xrpl@beta
# install peer deps
npm install react-native-randombytes
# install latest rn-nodeify
npm install rn-nodeify@latest --dev
After that, run the following command:
# install node core shims and recursively hack package.json files
# in ./node_modules to add/update the "browser"/"react-native" field with relevant mappings
./node_modules/.bin/rn-nodeify --hack --install
Enable crypto
:
rn-nodeify
will create a shim.js
file in the project root directory.
Open it and uncomment the line that requires the crypto module:
// If using the crypto shim, uncomment the following line to ensure
// crypto is loaded first, so it can populate global.crypto
require('crypto')
Import shim
in your project (it must be the first line):
import './shim'
...
Until official support for Deno is added, you can use the following work-around to use xrpl.js
with Deno:
import xrpl from 'https://dev.jspm.io/npm:xrpl';
(async () => {
const api = new (xrpl as any).RippleAPI({ server: 'wss://s.altnet.rippletest.net:51233' });
const address = 'rH8NxV12EuV...khfJ5uw9kT';
api.connect().then(() => {
api.getBalances(address).then((balances: any) => {
console.log(JSON.stringify(balances, null, 2));
});
});
})();
We have a low-traffic mailing list for announcements of new xrpl.js releases. (About 1 email per week)
If you're using the XRP Ledger in production, you should run a rippled server and subscribe to the ripple-server mailing list as well.
To build the library for Node.js and the browser:
$ npm run build
The TypeScript compiler will output the resulting JS files in ./dist/npm/
.
webpack will output the resulting JS files in ./build/
.
For details, see the scripts
in package.json
.
cd
into the repository and install dependencies with npm install
npm test
Run npm run lint
to lint the code with eslint
.
Update the documentation by running npm run docgen
.
FAQs
A TypeScript/JavaScript API for interacting with the XRP Ledger in Node.js and the browser
The npm package @ledhed2222/ripple-lib receives a total of 1 weekly downloads. As such, @ledhed2222/ripple-lib popularity was classified as not popular.
We found that @ledhed2222/ripple-lib demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.