data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Status: Alpha
General purpose library for the EOS blockchain.
Eos = require('eosjs') // Or Eos = require('./src')
// API, note: testnet uses eosd at localhost (until there is a testnet)
eos = Eos.Testnet()
// All API methods print help when called with no-arguments.
eos.getBlock()
// Next, your going to need eosd running on localhost:8888
// If a callback is not provided, a Promise is returned
eos.getBlock(1).then(result => {console.log(result)})
// Parameters can be sequential or an object
eos.getBlock({block_num_or_id: 1}).then(result => console.log(result))
// Callbacks are similar
callback = (err, res) => {err ? console.error(err) : console.log(res)}
eos.getBlock(1, callback)
eos.getBlock({block_num_or_id: 1}, callback)
// Provide an empty object or a callback if an API call has no arguments
eos.getInfo({}).then(result => {console.log(result)})
API methods and documentation are generated from:
options = {broadcast: true, sign: true, expireInSeconds: N, debug: false}
Eos = require('eosjs') // Or Eos = require('./src')
eos = Eos.Testnet({keyProvider: '5KQwrPbwdL6PhXujxW37FSSQZ1JiwsST4cqQzDeyXtP79zkvFD3'})
// All Eos transactions as of the last update are available. Run with no
// arguments to print usage.
eos.transfer()
// Usage with options
options = {broadcast: false}
eos.transfer({from: 'inita', to: 'initb', amount: 1, memo: ''}, options)
// Object or ordered args may be used. Options are optional.
eos.transfer('inita', 'initb', 1, 'memo')
// A broadcast boolean may be provided as a shortcut for {broadcast: false}
eos.transfer('inita', 'initb', 1, '', false)
Read-write API methods and documentation are generated from this schema.
For more advanced signing, see keyProvider
in the unit test.
Shorthand is available for some types such as Asset and Authority.
For example:
'10 EOS'
is shorthand for {amount: 10, symbol: 'EOS'}
'EOS6MRy..'
is shorthand for {threshold: 1, keys: [key: 'EOS6MRy..', weight: 1]}
Eos = require('eosjs') // Or Eos = require('./src')
initaPrivate = '5KQwrPbwdL6PhXujxW37FSSQZ1JiwsST4cqQzDeyXtP79zkvFD3'
initaPublic = 'EOS6MRyAjQq8ud7hVNYcfnVPJqcVpscN5So8BhtHuGYqET5GDW5CV'
keyProvider = initaPrivate
eos = Eos.Testnet({keyProvider})
eos.newaccount({
creator: 'inita',
name: 'mynewacct',
owner: initaPublic,
active: initaPublic,
recovery: 'inita',
deposit: '1 EOS'
})
Eos = require('eosjs') // Or Eos = require('./src')
let {ecc} = Eos.modules
initaPrivate = '5KQwrPbwdL6PhXujxW37FSSQZ1JiwsST4cqQzDeyXtP79zkvFD3'
// New deterministic key for the currency account. Only use a simple
// seedPrivate in production if you want to give away money.
currencyPrivate = ecc.seedPrivate('currency')
currencyPublic = ecc.privateToPublic(currencyPrivate)
keyProvider = [initaPrivate, currencyPrivate]
eos = Eos.Testnet({keyProvider})
eos.newaccount({
creator: 'inita',
name: 'currency',
owner: currencyPublic,
active: currencyPublic,
recovery: 'inita',
deposit: '1 EOS'
})
contractDir = `${process.env.HOME}/eosio/eos/build/contracts/currency`
wast = fs.readFileSync(`${contractDir}/currency.wast`)
abi = fs.readFileSync(`${contractDir}/currency.abi`)
// Publish contract to the blockchain
eos.setcode('currency', 0, 0, wast, abi)
// eos.contract(code<string>, [options], [callback])
eos.contract('currency').then(currency => {
// Transfer is one of the actions in currency.abi
currency.transfer('currency', 'inita', 10)
})
Blockchain level atomic operations. All will pass or fail.
Eos = require('eosjs') // Or Eos = require('./src')
keyProvider = [
'5KQwrPbwdL6PhXujxW37FSSQZ1JiwsST4cqQzDeyXtP79zkvFD3',
Eos.modules.ecc.seedPrivate('currency')
]
testnet = Eos.Testnet({keyProvider})
// if either transfer fails, both will fail (1 transaction, 2 messages)
testnet.transaction(eos =>
{
eos.transfer('inita', 'initb', 1, '')
eos.transfer('inita', 'initc', 1, '')
// Returning a promise is optional (but handled as expected)
}
// [options],
// [callback]
)
// transaction on a single contract
testnet.transaction('currency', currency => {
currency.transfer('inita', 'initd', 1)
})
// mix contracts in the same transaction
testnet.transaction(['currency', 'eos'], ({currency, eos}) => {
currency.transfer('inita', 'initd', 1)
eos.transfer('inita', 'initd', 1, '')
})
// contract lookups then transactions
testnet.contract('currency').then(currency => {
currency.transaction(tr => {
tr.transfer('inita', 'initd', 1)
tr.transfer('initd', 'inita', 1)
})
currency.transfer('inita', 'inite', 1)
})
// Note, the contract method does not take an array. Just use Await or yield
// if multiple contracts are needed outside of a transaction.
A manual transaction provides for more flexibility.
Eos = require('eosjs') // Or Eos = require('./src')
eos = Eos.Testnet({keyProvider: '5KQwrPbwdL6PhXujxW37FSSQZ1JiwsST4cqQzDeyXtP79zkvFD3'})
eos.transaction({
scope: ['inita', 'initb'],
messages: [
{
code: 'eos',
type: 'transfer',
authorization: [{
account: 'inita',
permission: 'active'
}],
data: {
from: 'inita',
to: 'initb',
amount: 7,
memo: ''
}
}
]
})
From time-to-time the eosjs and eosd binary format will change between releases
so you may need to start eosd
with the --skip-transaction-signatures
parameter
to get your transactions to pass.
Note, package.json
has a "main" pointing to ./lib
. The ./lib
folder is for
es2015 code built in a separate step. If your changing and testing code,
import from ./src
instead.
Eos = require('./src')
Use Node v8+ to package-lock.json
.
These libraries are exported from eosjs
or may be used separately.
var {api, ecc, json, Fcbuffer} = Eos.modules
git clone https://github.com/EOSIO/eosjs.git
cd eosjs
npm install
npm run build
# builds: ./dist/eos.js
<script src="eos.js"></script>
<script>
var eos = Eos.Testnet()
//...
</script>
Node 6+ and browser (browserify, webpack, etc)
React Native should work, create an issue if you find a bug.
FAQs
Talk to eos API
We found that eosjs demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.