
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
expo-web-sqlite
Advanced tools
Basically the same as `expo-sqlite` but `WebSQLDatabase` isn't deprecated in favor of the experimental, silent-erroring SQLiteDatabase. Provides access to a database that can be queried through a WebSQL-like API (https://www.w3.org/TR/webdatabase/). The d
Supply Chain Security
Vulnerability
Quality
Maintenance
License
This package is an effort to provide a truly stable version of expo-sqlite
for Expo SDK 49. This package does not sacrifice older stable features for new experimental ones. Note that the utility of this package depends on how the experimental Promise-based API fares in expo-sqlite
. The hope is that I can deprecate this package once said API becomes stable.
expo-sqlite
(except for installation instructions)Provides access to a database that can be queried through a WebSQL-like API (https://www.w3.org/TR/webdatabase/). The database is persisted across restarts of your app.
For managed Expo projects, please follow the installation instructions in the API documentation for the latest stable release.
For bare React Native projects, you must ensure that you have installed and configured the expo
package before continuing.
npx expo install expo-web-sqlite
Run npx pod-install
after installing the npm package.
No additional set up necessary.
Contributions are very welcome! Please refer to guidelines described in the contributing guide.
FAQs
Basically the same as `expo-sqlite` but `WebSQLDatabase` isn't deprecated in favor of the experimental, silent-erroring SQLiteDatabase. Provides access to a database that can be queried through a WebSQL-like API (https://www.w3.org/TR/webdatabase/). The d
The npm package expo-web-sqlite receives a total of 90 weekly downloads. As such, expo-web-sqlite popularity was classified as not popular.
We found that expo-web-sqlite demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.