
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@pinelab/vendure-plugin-coinbase
Advanced tools
Accept crypto payments via Coinbase Commerce in Vendure.
Add the plugin to your vendure-config.ts
:
plugins: [CoinbasePlugin];
coinbase-payment-handler
https://storefront/order/
. Your customer will be redirected
to this page + order code: https://storefront/order/897HH7HG7
https://<your-vendure-server>/payments/coinbase
You can now call the mutation createCoinbasePaymentIntent
to get a redirectUrl to the Coinbase hosted checkout page.
You can redirect your customer to this URL, so your customer can continue making a payment on the Coinbase platform.
After payment the customer will be redirected to https://storefront/order/897HH7HG7
Orders are NOT transitioned to PaymentSettled
directly after Coinbase redirects the customer to the confirmation page, because
crypto transactions can take some time to confirm. You should notify your customer with a message that the order will be
handled when their transaction is confirmed. This can take a few minutes.
Refunds are not supported. If you want to refund a payment done via Coinbase you need to manually do so. This plugin will not do refunds via Coinbase.
FAQs
Vendure plugin for Coinbase payments
We found that @pinelab/vendure-plugin-coinbase demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.