
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
lovefield-ts
Advanced tools
Lovefield Typescript port and modernization.
The port attempts to maintain API compatibility with original Lovefield. As a result, some parts may conflict with TypeScript best practice (e.g. interface name must start with capital I).
lib/base/lovefield_options.ts
. Users are supposed to define an object
following that interface and set options via the new API lf.options.set()
.
testing/debug_options.ts
.The project is set to use modern Typescript (3.8+) and Mocha/Chai/Sinon/Karma as its test framework. Compilation/test speed has improved significantly.
npm install
node node_modules/guppy-cli/bin/index.js pre-commit
Lovefield-ts uses gulp 4, which is incompatible with gulp 3 that original Lovefield uses. If you had installed gulp globally as suggested in README of Lovefield, please run:
npm uninstall -g gulp
Run gulp
to see the commands.
Please note that certain tests are only runnable in Karma (e.g. IndexedDB related tests), and these tests will be named *_spec.ts.
lib
: Lovefield main library source codetesting
: Facility code used for testingtests
: Tests for Lovefield main libraryout
: Temporary directory used to store intermediate files from tool chaindist
: Generated dist filescoverage
: Code coverage reportFAQs
Lovefield-TS: a relational database in TypeScript
The npm package lovefield-ts receives a total of 54 weekly downloads. As such, lovefield-ts popularity was classified as not popular.
We found that lovefield-ts demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.