
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
rdf-parser-csvw
Advanced tools
A CSV on the Web parser with RDF/JS Stream interface.
The package exports the parser as a class, so an instance must be created before it can be used.
The .import
method, as defined in the RDF/JS specification, must be called to do the actual parsing.
It expects a stream of strings.
The method will return a stream which emits the parsed quads.
The constructor accepts an options
object with the following optional keys:
metadata
: Use the metadata to convert the CSV to RDF.
The metadata must be given as a Dataset using the CSV on the Web ontology.
This options is required.baseIRI
: Use the IRI to create Named Nodes.
The value must be a String.
This options is required.factory
: Use an alternative RDF/JS data factory.
By default the reference implementation us used.timezone
: Use an alternative timezone to parse date and time values.
The value must be given as a String as defined in the Luxon documentation.
By default local
will be used.relaxColumnCount
: Don't throw an error if a row has a column count which doesn't match the headers column coun.skipLinesWithError
: Skip lines with error instead of throwing an error and stop parsing.
This is mainly useful for debugging and should not be used in production environments.It's also possible to pass options as second argument to the .import
method.
The options from the constructor and the .import
method will be merged together.
FAQs
CSV on the Web parser
The npm package rdf-parser-csvw receives a total of 5,296 weekly downloads. As such, rdf-parser-csvw popularity was classified as popular.
We found that rdf-parser-csvw demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.