
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
The goal of F2 is to define a development standard for the financial services industry that offers a cost saving, risk-reducing method for building innovative, multi-provider solutions.
F2 makes integration simple, standardized and modern. It's the next-generation of content integration created by the team who has the most experience developing integrated solutions in financial services.
Visit docs.openf2.org for a list of all available demos, including jsFiddle and Codepen examples.
F2 is currently maintained by IHS Markit Digital.
Join the team and help contribute to F2 on GitHub. Begin by reading our contribution guidelines, and then start by forking the repo, sending pull requests, or submitting issues.
Thank you to the growing list of contributors!
PM> Install-Package F2
bower install F2
The F2 development standard and API docs are available at docs.openf2.org.
Be sure you have cloned this repository and have Node.js installed, then run the following command from the project root:
$> npm install
This command will install all dependencies needed to build F2.
After any edits to the core F2 javascript or docs, run this task to compile dist:
$> npm run build
For other helpful tasks, see the scripts
section of the package.json
.
The latest version of F2.js will always be in master
.
In accordance with industry standards, F2 is currently maintained, in as far as reasonably possible, under the Semantic Versioning guidelines. Releases will be numbered with the following format:
<major>.<minor>.<patch>
For more information on SemVer, please visit SemVer.org.
It is our goal to make upgrading to the latest version of F2 a minor effort for development teams. Read more in the Docs.
Have a question? Find a bug? Open an Issue on GitHub or send an email to info@openf2.org.
To track bugs, issues and enhancement requests, we are using Issues on GitHub.
Copyright © 2021 IHS Markit Digital
"F2" is licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at:
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
Please note that F2 ("Software") may contain third party material that Markit On Demand Inc. has a license to use and include within the Software (the "Third Party Material"). A list of the software comprising the Third Party Material and the terms and conditions under which such Third Party Material is distributed are reproduced in the ThirdPartyMaterial.md file. The inclusion of the Third Party Material in the Software does not grant, provide nor result in you having acquiring any rights whatsoever, other than as stipulated in the terms and conditions related to the specific Third Party Material, if any.
FAQs
An open framework for the financial services industry.
The npm package f2 receives a total of 7 weekly downloads. As such, f2 popularity was classified as not popular.
We found that f2 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.