Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@quarryprotocol/quarry-sdk
Advanced tools
An open protocol for launching liquidity mining programs on Solana.
Quarry was built with the intention of helping more Solana projects launch on-chain liquidity mining programs. It is currently standard for projects to manually send tokens to addresses-- while this is better than no distribution, it would be much better for the growth of the ecosystem if liquidity mining programs were composable and enforceable on-chain.
Quarry Protocol has been audited by Quantstamp. View the audit report here.
Program addresses are the same on devnet, testnet, and mainnet-beta.
QMMD16kjauP5knBwxNUJRZ1Z5o3deBuFrqVjBVmmqto
QMNeHCGYnLVDn1icRAfQZpjPLBNkfGbSKRB83G5d8KB
QMWoBmAyJLAsA1Lh9ugMTw2gciTihncciphzdNzdZYV
QoP6NfrQbaGnccXQrMLUkog2tQZ4C1RFgJcwDnT8Kmz
QRDxhMw1P2NEfiw5mYXG79bwfgHTdasY2xNP76XSea9
QREGBnEj9Sa5uR91AV8u3FxThgP5ZCvdZUW2bHAkfNc
Documentation is a work in progress. For now, one should read the end-to-end tests of the SDK.
We soon plan on releasing a React library to make it easy to integrate Quarry with your frontend.
Quarry Protocol is licensed under the GNU Affero General Public License v3.0.
In short, this means that any changes to this code must be made open source and available under the AGPL-v3.0 license, even if only used privately. If you have a need to use this program and cannot respect the terms of the license, please message us our legal team directly at legal@quarry.so.
FAQs
Quarry Protocol SDK
The npm package @quarryprotocol/quarry-sdk receives a total of 2,975 weekly downloads. As such, @quarryprotocol/quarry-sdk popularity was classified as popular.
We found that @quarryprotocol/quarry-sdk demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.