Security News
Supply Chain Attack Detected in Solana's web3.js Library
A supply chain attack has been detected in versions 1.95.6 and 1.95.7 of the popular @solana/web3.js library.
captain-log
Advanced tools
Automating the logs from your favorite captains
npm install captain-log
const captain = require('captain-log')
captain([{
title: 'What happened (ongoing)', // This will be the title of this group of issues
repo: 'ipld/specs', // this is the repo to get these from
state: 'open', // want open issues or closed ones?
labels: [], // any label to filter?
exclude_labels: ['needs spec'], // any label to exclude?
todo: true, // want to show the list as a todo?
since: '2016-09-10T12:00:00Z', // want to get them from a particular time?
exclude: [13], // want to exclude a particular issue?
prefix: ':tada:' // wants to prefix each issues with a special emoji 🎉?
}] [, optionallyYourBasicAuth])
will output
### What happened (ongoing)
- :tada: [ ] #19 : Idea for permanent mutable links
- :tada: [ ] #14 : Adding Introduction, Abstract and Scope
- :tada: [ ] #12 : Skeleton of IPLD v1 spec
- :tada: [ ] #4 : Selectors: Use cases (from Q3 Workshop)
See a better demo for ipld/specs
(code here)
I learned the practice of writing a captain.log from @daviddias in his work on js-ipfs
(see his really cool log). When I started my captain.log I found really useful to list all the different issues that are open, closed, that need a spec that had something happening & so on. This process is very slow for humans but fast for machines :)
MIT
FAQs
The log from your favorite captains
The npm package captain-log receives a total of 2 weekly downloads. As such, captain-log popularity was classified as not popular.
We found that captain-log demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
A supply chain attack has been detected in versions 1.95.6 and 1.95.7 of the popular @solana/web3.js library.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.