
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
@nevermined-io/contract-tools
Advanced tools
The Nevermined Zeppelin OS contract management framework
💧 The Nevermined Zeppelin OS contract management framework nevermined.io
npm i @nevermined-io/contract-tools
To deploy the contract MyContract do the following:
const {
deployContracts
} = require('@nevermined-io/contract-tools')
await deployContracts({
// web3, coming from truffle
web3,
// artifacts, coming from truffle
artifacts,
evaluateContracts: ({
contracts = []
} = {}) => {
// decide which contracts to deploy here
},
initializeContracts: async ({
contracts,
roles,
network,
verbose = true
} = {}) => {
// call the initializer of each contract here
},
setupContracts: async ({
addressBook,
artifacts,
roles,
verbose
} = {}) => {
// call the contracts here to set them up
},
contracts: [
'MyContract'
],
// forces the creation of wallets all the time
forceWalletCreation: true,
// clean zos session files
clean: true,
// clean zos files and wallets on the current network as well
deeperClean: true,
// are we going to deploy to a testnet or a mainnet?
testnet: false,
// be verbose or not
verbose: true
})
An example of the whole flow can be found here
An example of evaluateContracts can be found here
An example of initializeContracts can be found here
An example of setupContracts can be found here
Run tests with npm run test.
This project builds on top of the work done in open source projects:
This project is based in the Ocean Protocol Dori project. It keeps the same Apache v2 License and adds some improvements. See NOTICE file.
Copyright 2020 Keyko GmbH
This product includes software developed at
BigchainDB GmbH and Ocean Protocol (https://www.oceanprotocol.com/)
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
FAQs
The Nevermined Zeppelin OS contract management framework
We found that @nevermined-io/contract-tools demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.