
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@stellar/stellar-base
Advanced tools
The stellar-base library is the lowest-level stellar helper library. It consists of classes to read, write, hash, and sign the xdr structures that are used in stellar-core. This is an implementation in JavaScript that can be used on either Node.js or web browsers.
Warning! The Node version of this package uses the
sodium-native
package, a native implementation of Ed25519 in Node.js, as an optional dependency. This means that if for any reason installation of this package fails,stellar-base
will fallback to the much slower implementation contained intweetnacl
.If you'd explicitly prefer not to install the
sodium-native
package, pass the appropriate flag to skip optional dependencies when installing this package (e.g.--no-optional
if usingnpm install
or--without-optional
usingyarn install
).If you are using
stellar-base
in a browser you can ignore this. However, for production backend deployments you should most likely be usingsodium-native
. Ifsodium-native
is successfully installed and working,StellarBase.FastSigning
variable will be equaltrue
. Otherwise it will befalse
.
Using yarn to include js-stellar-base in your own project:
yarn add @stellar/stellar-base
For browsers, use Bower to install it. It exports a
variable StellarBase
. The example below assumes you have stellar-base.js
relative to your html file.
<script src="stellar-base.js"></script>
<script>
console.log(StellarBase);
</script>
yarn add @stellar/stellar-base
var StellarBase = require('@stellar/stellar-base');
bower install stellar-base
<script src="./bower_components/stellar-base/stellar-base.js"></script>
<script>
console.log(StellarBase);
</script>
If you don't want to use install Bower, you can copy built JS files from the bower-js-stellar-base repo.
<script src="https://cdnjs.cloudflare.com/ajax/libs/stellar-base/{version}/stellar-base.js"></script>
<script>
console.log(StellarBase);
</script>
Note that this method relies using a third party to host the JS library. This may not be entirely secure.
Make sure that you are using the latest version number. They can be found on the releases page in Github.
We support the oldest LTS release of Node, which is currently 18.x. Please likewise install and develop on Node 16 so you don't get surprised when your code works locally but breaks in CI.
If you work on several projects that use different Node versions, you might find helpful to install a NodeJS version manager:
This project uses Yarn to manages its dependencies. To install Yarn, follow the project instructions available at https://yarnpkg.com/en/docs/install.
git clone https://github.com/stellar/js-stellar-base.git
cd js-stellar-base
yarn
While you're making changes, make sure to regularly run the linter to catch any linting errors (in addition to making sure your text editor supports ESLint)
yarn lint
as well as fixing any formatting errors with
yarn fmt
If you're working on a file not in src
, limit your code to Node 6.16 ES! See
what's supported here: https://node.green/. (Our npm library must support
earlier versions of Node, so the tests need to run on those versions.)
XDR updates are complicated due to the fact that you need workarounds for bugs in the generator, formatter, or a namespace adjustment.
make reset-xdr
sed -ie s/\"/\'/g types/{curr,next}.d.ts
to minimize the diff (the generator's formatter uses "
but the repo uses '
).xdr.Operation
into a hidden namespace to avoid conflicts with the SDK's Operation
.type Hash = Opaque[]
is a necessary alias that doesn't get generatedHyper
, UnsignedHyper
, and ScSpecEventV0
need their signatures
fixed because linting wants an Array
instead of a naked []
.SCSYMBOL_LIMIT
in src/curr_generated.js
)As an example PR to follow, stellar-base#800 has detailed steps for each part of the process.
For information on how to use js-stellar-base, take a look at the docs in the docs folder.
To run all tests:
yarn test
To run a specific set of tests:
yarn test:node
yarn test:browser
Tests are also run automatically in Github Actions for every master commit and pull request.
Documentation for this repo lives inside the docs folder.
Please see the CONTRIBUTING.md for details on how to contribute to this project.
npm version [<newversion> | major | minor | patch | premajor | preminor | prepatch | prerelease]
A new version will be published to npm and Bower by GitHub Actions.
npm >= 2.13.0 required. Read more about npm version.
js-stellar-base is licensed under an Apache-2.0 license. See the LICENSE file for details.
v14.0.0
: Protocol 23
sodium-native
and tweetnacl
dependencies have been replaced with @noble/curves
(#802).StrKey
(#799).Address
(#801).nativeToScVal
to convert arrays with differing types to smart contract values, e.g., nativeToScVal([1, "x", "y"], { type: [ "i128", "symbol" ]})
will give you a Vec<i128, symbol, string>
(#803).Buffer.subarray
polyfill introduced in #733 in v11.0.1 as a workaround for React Native's Hermes engine. Please use @exodus/patch-broken-hermes-typed-arrays
as an alternative, if needed (#795).MuxedAccount.parseBaseAddress
from TypeScript definitions (#797).FAQs
Low-level support library for the Stellar network.
The npm package @stellar/stellar-base receives a total of 0 weekly downloads. As such, @stellar/stellar-base popularity was classified as not popular.
We found that @stellar/stellar-base demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 8 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.