Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
i18n-json-tool
Advanced tools
Convert JSON i18n files via the yandex api for quick internationalization testing
i18n-translate-tool was built out of the necessity to leverage internationalization before the copywriters are done translating your strings. It allows you to leverage either a CLI interface, or translate on the fly within your app returning you a JSON copy of whatever you give it.
Currently it supports:
CLI Usage
Usage: translate [options] <file>
Options:
-s, --service <service> google, yandex or bing
-k, --key <key> API key
-i, --iso <code> isoCode to translate to
-r, --regexp <expression> regular expression to filter interpolations
-h, --help output usage information
example execution
translate ./example/en.json -i nl -k some_key -r "{{([^}]+?)}}"
In the above example following string will be translated:
"n2": "with {{some}} regexs in it"
to dutch
"n2": "met {{some}} regexs in het"
As you can see the regex allows interpolations to stay intact while translating.
Web Usage
import translate from "i18n-json-tool";
const translations = {
key1: "Hello world!"
};
translate({
apiKey,
isoCode: "nl",
translations,
service, // defaults to yandex (optional)
regexp // defaults to nothing (optional)
}).then(results => console.log(results));
Please feel free to open any tickets with feature requests but make sure to document:
FAQs
Convert JSON i18n files via the yandex api for quick internationalization testing
We found that i18n-json-tool demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.