
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
appx-manifest-version
Advanced tools
Tool used to increment the version number of an AppxManifest.xml
file.
The package is published to npmjs.com. You can install with:
npm install -g appx-manifest-version
or
npm install appx-manifest-version --save-dev
appx-version manifest_file_path
This will load the Appx manifest XML file manifest_file_path
, locate
the Package/Identity@Version
field and increment the final numerical
field after a period (.
). Then it will overwrite the original manifest
file with the updated content.
You can call into the appx-manifest-version
module from your own code
as follows:
const appxVersion = require('appx-manifest-version');
// currentManifestString is a string containing the manifest contents
// returns a Promise
appxVersion.incrementVersion(currentManifestString)
.then(data => {
console.log(data.version); // new version string
console.log(data.manifest); // new manifest string
})
.catch(err => {
console.error(err.status); // error code
console.error(err.details); // error details string
});
// manifestPath is the path to the manifest XML file
// overwriteCurrent is true if the current XML file should be updated
// returns a Promise
appxVersion.incrementVersionFile(manifestPath,overwriteCurrent)
.then(data => {
console.log(data.version); // new version string
console.log(data.manifest); // new manifest string
})
.catch(err => {
console.error(err.status); // error code
console.error(err.details); // error details string
});
See the LICENSE file.
FAQs
Tool to upgrade the version of an Appx Manifest file.
The npm package appx-manifest-version receives a total of 3 weekly downloads. As such, appx-manifest-version popularity was classified as not popular.
We found that appx-manifest-version demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.