
Research
npm Malware Targets Telegram Bot Developers with Persistent SSH Backdoors
Malicious npm packages posing as Telegram bot libraries install SSH backdoors and exfiltrate data from Linux developer machines.
@mpetrunic/eth2-spec-tests
Advanced tools
This repository contains test vectors for the Eth 2.0 spec. Other types of testing (network, fuzzing, benchmarking, etc.) are currently a work in progress, and will be hosted in separate repositories. The intention of this repository is to provide a solid
This repository contains test vectors for the Eth 2.0 spec. Other types of testing (network, fuzzing, benchmarking, etc.) are currently a work in progress, and will be hosted in separate repositories. The intention of this repository is to provide a solid base for Eth 2.0 clients to consume as part of their unit-testing efforts around spec behavior.
The tests are YAML files following the general testing format.
The generators that are responsible for generating all of the spec tests can be found in ethereum/eth2.0-specs/test_generators.
New tests can be added by creating a generator in the specs repository, or adding functionality to an existing generator. Generators are small and easy to write, and can use the pythonized-spec to build expected test outputs: see documentation
Note that this repository is growing over time as the spec evolves, and more test-generation code is being added. The YAML test-vectors are tracked using Git LFS, to accommodate for large test vectors (Take Eth 1.0 tests repository size as an example).
See LICENSE file.
FAQs
This repository contains test vectors for the Eth 2.0 spec. Other types of testing (network, fuzzing, benchmarking, etc.) are currently a work in progress, and will be hosted in separate repositories. The intention of this repository is to provide a solid
The npm package @mpetrunic/eth2-spec-tests receives a total of 16 weekly downloads. As such, @mpetrunic/eth2-spec-tests popularity was classified as not popular.
We found that @mpetrunic/eth2-spec-tests demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Malicious npm packages posing as Telegram bot libraries install SSH backdoors and exfiltrate data from Linux developer machines.
Security News
pip, PDM, pip-audit, and the packaging library are already adding support for Python’s new lock file format.
Product
Socket's Go support is now generally available, bringing automatic scanning and deep code analysis to all users with Go projects.