
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@rebilly/risk-data-collector
Advanced tools
Microlibrary that collects browser data for risk assessment
Collect browser data for risk assessment purposes.
risk-data-collector
is a client side microlibrary which collects user data required for the risk assessment component of 3DS v2. It is expected to be used:
approvalUrl
for the 3DS processcolorDepth
javaEnabled
language
screenHeight
screenWidth
timeZoneOffset
deviceFingerprintHash
risk-data-collector
is distributed in two ways:
RiskDataCollector
global namespace and can be used like so:<html>
<head>
<script src="https://unpkg.com/@rebilly/risk-data-collector"></script>
</head>
<body>
<script type="text/javascript">
(async () => {
const browserData = await RiskDataCollector.collectData();
console.log(`browserData is: ${JSON.stringify(browserData)}`)
})()
</script>
</body>
<html>
yarn add @rebilly/risk-data-collector
npm install @rebilly/risk-data-collector
Which can be imported and used like so:
import {collectData} from '@rebilly/risk-data-collector';
(async () => {
const browserData = await collectData();
console.log(`browserData is: ${JSON.stringify(browserData)}`)
})()
FAQs
Microlibrary that collects browser data for risk assessment
The npm package @rebilly/risk-data-collector receives a total of 70 weekly downloads. As such, @rebilly/risk-data-collector popularity was classified as not popular.
We found that @rebilly/risk-data-collector demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.