
Research
Malicious NuGet Packages Typosquat Nethereum to Exfiltrate Wallet Keys
The Socket Threat Research Team uncovered malicious NuGet packages typosquatting the popular Nethereum project to steal wallet keys.
@pgtyped/cli
Advanced tools
This package provides the `pgtyped` CLI. The `pgtyped` CLI can work in build and watch mode.
This package provides the pgtyped
CLI.
The pgtyped
CLI can work in build and watch mode.
The CLI supports two flags:
-c config_file_path.json
to pass the config file path.-w
to start in watch mode.Running the CLI:
npx pgtyped -w -c config.json
PgTyped supports common PostgreSQL environment variables:
PGHOST
PGUSER
PGPASSWORD
PGDATABASE
PGPORT
These variables will override values provided in config.json
.
Config file format (config.json
):
{
// You can specify as many transforms as you want
// Only TS and SQL files (modes) are supported at the moment
"transforms": [
{
"mode": "sql", // SQL mode
"include": "**/*.sql", // SQL files pattern to scan for queries
"emitTemplate": "{{dir}}/{{name}}.queries.ts" // File name template to save generated files
},
{
"mode": "ts", // TS mode
"include": "**/action.ts", // TS file pattern to scan for queries
"emitTemplate": "{{dir}}/{{name}}.types.ts" // File name template to save generated files
}
],
"srcDir": "./src/", // Directory to scan or watch for query files
"failOnError": false, // Whether to fail on a file processing error and abort generation (can be omitted - default is false)
"camelCaseColumnNames": false, // convert to camelCase column names of result interface
"db": {
"dbName": "testdb", // DB name
"user": "user", // DB username
"password": "password", // DB password (optional)
"host": "127.0.0.1" // DB host (optional)
}
}
By default, PgTyped saves generated files in the same folder as the source files it parses.
This behavior can be customized using the emitTemplate
config parameter.
In that template, four parameters are available for interpolation: root
, dir
, base
, name
and ext
.
For example, when parsing source/query file /home/user/dir/file.sql
, these parameters are assigned the following values:
βββββββββββββββββββββββ¬βββββββββββββ
β dir β base β
ββββββββ¬ ββββββββ¬ββββββ€
β root β β name β ext β
" / home/user/dir / file .sql "
ββββββββ΄βββββββββββββββ΄βββββββ΄ββββββ
(All spaces in the "" line should be ignored. They are purely for formatting.)
This package is part of the PgTyped project.
Refer to root README for details.
FAQs
Unknown package
The npm package @pgtyped/cli receives a total of 21,894 weekly downloads. As such, @pgtyped/cli popularity was classified as popular.
We found that @pgtyped/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago.Β It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
The Socket Threat Research Team uncovered malicious NuGet packages typosquatting the popular Nethereum project to steal wallet keys.
Product
A single platform for static analysis, secrets detection, container scanning, and CVE checksβbuilt on trusted open source tools, ready to run out of the box.
Product
Socket is launching experimental protection for the Hugging Face ecosystem, scanning for malware and malicious payload injections inside model files to prevent silent AI supply chain attacks.