
Security News
Risky Biz Podcast: Making Reachability Analysis Work in Real-World Codebases
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
This SDK simplifies the development of C–ATTS recipes. It provides a set of functions for fetching query results, running processor scripts, and validating schema items against a recipe's schema.
When developing recipes, most likey you will want to use the pre-packaged catts
CLI tool instead of this SDK. The tool fetches query results, runs processor scripts, and validates schema items against the recipe's schema. You can find the CLI tool here: catts-cli.
For some examples of recipes, see the catts-recipes repository.
C–ATTS, or Composite Attestations, is a new type of attestation that combines data from multiple sources to form a unified and verifiable credential.
To learn more, see the C–ATTS website.
npm i catts-sdk
parseRecipe(input: unknown): Recipe
input
(unknown): The input to be parsed.Recipe
object if the input is valid.fetchQuery(query: Query): Promise<any>
query
(Query): The GraphQL query, including endpoint, query string, and variables.runProcessor({ processor, queryResults }: { processor: string, queryResults: any }): Promise<string>
processor
(string): The processor JavaScript code to be executed.queryResults
(any): An array of query results in JSON format.validateProcessorResult({ processorResult }: { processorResult: string }): Promise<SchemaItem[]>
processorResult
(string): The raw result of the processor script as a string.SchemaItem
objects if the processor result is valid.validateSchemaItems({ schemaItems, recipe }: { schemaItems: SchemaItem[], recipe: Recipe }): Promise<any>
schemaItems
(SchemaItem[]): An array of schema items to be validated.recipe
(Recipe): The recipe containing the schema to validate against.getSchemaUid({ schema, resolver, revokable }: { schema: string, resolver: string, revokable: boolean }): string
schema
(string): The schema string.resolver
(string): The resolver address.revokable
(boolean): The revokable flag.import { fetchQuery, runProcessor, validateProcessorResult, validateSchemaItems, getSchemaUid } from 'catts-sdk';
// Example usage of fetchQuery
const query = {
endpoint: 'https://api.example.com/graphql',
query: `
query ($id: ID!) {
user(id: $id) {
name
email
}
}
`,
variables: { id: '12345' },
};
fetchQuery(query).then(result => console.log(result));
// Example usage of runProcessor
const processor = `
return queryResult.map(user => ({
name: user.name,
email: user.email,
}));
`;
runProcessor({ processor, queryResults: [{ name: 'John Doe', email: 'john.doe@example.com' }] })
.then(result => console.log(result));
// Example usage of validateProcessorResult
const processorResult = '[{"name": "John Doe", "email": "john.doe@example.com"}]';
validateProcessorResult({ processorResult })
.then(schemaItems => console.log(schemaItems));
// Example usage of getSchemaUid
const schemaUid = getSchemaUid({ schema: 'userSchema', resolver: '0x1234567890abcdef', revokable: true });
console.log(schemaUid);
This project is licensed under the MIT License. See the LICENSE file for more details.
Contributions are welcome! Please open an issue or submit a pull request if you have any suggestions or improvements.
FAQs
Facilitates the local development of C-ATTS recipes.
The npm package catts-sdk receives a total of 0 weekly downloads. As such, catts-sdk popularity was classified as not popular.
We found that catts-sdk demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.
Security News
CISA’s 2025 draft SBOM guidance adds new fields like hashes, licenses, and tool metadata to make software inventories more actionable.