
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
convex-svelte
Advanced tools
[Convex](https://www.convex.dev/) is the typesafe backend-as-a-service with realtime updates, server functions, crons and scheduled jobs, file storage, vector search, and more.
Convex is the typesafe backend-as-a-service with realtime updates, server functions, crons and scheduled jobs, file storage, vector search, and more.
Receive live updates to Convex query subscriptions and call mutations and actions from Svelte with convex-svelte
.
To install:
npm install convex convex-svelte
Run npx convex init
to get started with Convex.
See the example app live.
convex-svelte
provides a setupConvex()
function which takes a Convex deployment URL,
a useConvexClient()
which returns a ConvexClient
used to set authentication credentials and run Convex mutations and actions,
and a useQuery()
function for subscribing to Convex queries.
Call setupConvex()
in a component above the components that need to Convex queries
and use useQuery()
components where you need to listen to the query.
See +layout.svelte for setupConvex()
<script>
import { PUBLIC_CONVEX_URL } from '$env/static/public';
setupConvex(PUBLIC_CONVEX_URL);
</script>
and Chat.svelte for how to use useQuery()
<script>
const query = useQuery(api.messages.list, () => ({ muteWords }), {
useResultFromPreviousArguments: true
});
</script>
...
{#if query.isLoading}
Loading...
{:else if query.error != null}
failed to load: {query.error.toString()}
{:else}
<ul>
{#each query.data as message}
<li>
<span>{message.author}</span>
<span>{message.body}</span>
</li>
{/each}
</ul>
{/if}
Running a mutation looks like
<script>
const client = useConvexClient();
let toSend = $state('');
let author = $state('me');
function onSubmit(e: SubmitEvent) {
const data = Object.fromEntries(new FormData(e.target as HTMLFormElement).entries());
client.mutation(api.messages.send, {
author: data.author as string,
body: data.body as string
});
}
</script>
<form on:submit|preventDefault={onSubmit}>
<input type="text" id="author" name="author" />
<input type="text" id="body" name="body" bind:value={toSend} />
<button type="submit" disabled={!toSend}>Send</button>
</form>
In production build pipelines use the build command
npx convex deploy --cmd-url-env-var-name PUBLIC_CONVEX_URL --cmd 'npm run build'
to build your Svelte app and deploy Convex functions.
Clone this repo and install dependencies with npm install
then start a development server:
npm run dev
This will run you through creating a Convex account and a deployment.
Everything inside src/lib
is part of the library, everything inside src/routes
is an example app.
To build the library:
npm run package
To create a production version of the showcase app:
npm run build
You can preview the production build with npm run preview
.
To deploy your app, you may need to install an adapter for your target environment.
Go into the package.json
and give your package the desired name through the "name"
option. Also consider adding a "license"
field and point it to a LICENSE
file which you can create from a template (one popular option is the MIT license).
To publish your library to npm:
npm publish
FAQs
[Convex](https://www.convex.dev/) is the typesafe backend-as-a-service with realtime updates, server functions, crons and scheduled jobs, file storage, vector search, and more.
The npm package convex-svelte receives a total of 2,313 weekly downloads. As such, convex-svelte popularity was classified as popular.
We found that convex-svelte demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 13 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.