
Security News
Rust RFC Proposes a Security Tab on crates.io for RustSec Advisories
Rust’s crates.io team is advancing an RFC to add a Security tab that surfaces RustSec vulnerability and unsoundness advisories directly on crate pages.
Deprecated - consider migrating to xrpl.js: https://xrpl.org/xrpljs2-migration-guide.html
This library (ripple-lib 1.x) has been deprecated in favor of xrpl.js version 2+.
A JavaScript/TypeScript API for interacting with the XRP Ledger
This library is for integrating a JavaScript/TypeScript app with the XRP Ledger and supports functionality such as IOUs, payment paths, the decentralized exchange, account settings, payment channels, escrows, multi-signing, and more.
Use the above link to view the full reference documentation.
rippled server from Node.js or a web browsernpm may work but we use yarn.lock.See also: RippleAPI Beginners Guide
In an existing project (with package.json), install ripple-lib:
$ yarn add ripple-lib
Then see the documentation.
If you want to use ripple-lib with React Native you will need to have some of the NodeJS modules available. To help with this you can use a module like rn-nodeify.
Install dependencies (you can use npm as well):
yarn add react-native-crypto
yarn add ripple-lib
# install peer deps
yarn add react-native-randombytes
# install latest rn-nodeify
yarn add rn-nodeify@latest --dev
After that, run the following command:
# install node core shims and recursively hack package.json files
# in ./node_modules to add/update the "browser"/"react-native" field with relevant mappings
./node_modules/.bin/rn-nodeify --hack --install
Enable crypto:
rn-nodeify will create a shim.js file in the project root directory.
Open it and uncomment the line that requires the crypto module:
// If using the crypto shim, uncomment the following line to ensure
// crypto is loaded first, so it can populate global.crypto
require('crypto')
Import shim in your project (it must be the first line):
import './shim'
...
Until official support for Deno is added, you can use the following work-around to use ripple-lib with Deno:
import ripple from 'https://dev.jspm.io/npm:ripple-lib';
(async () => {
const api = new (ripple as any).RippleAPI({ server: 'wss://s.altnet.rippletest.net:51233' });
const address = 'rH8NxV12EuV...khfJ5uw9kT';
api.connect().then(() => {
api.getBalances(address).then((balances: any) => {
console.log(JSON.stringify(balances, null, 2));
});
});
})();
We have a low-traffic mailing list for announcements of new ripple-lib releases. (About 1 email per week)
If you're using the XRP Ledger in production, you should run a rippled server and subscribe to the ripple-server mailing list as well.
To build the library for Node.js and the browser:
$ yarn build
The TypeScript compiler will output the resulting JS files in ./dist/npm/.
webpack will output the resulting JS files in ./build/.
For details, see the scripts in package.json.
cd into the repository and install dependencies with yarn installyarn testRun yarn lint to lint the code with eslint.
Do not edit ./docs/index.md directly because it is a generated file.
Instead, edit the appropriate .md.ejs files in ./docs/src/.
If you make changes to the JSON schemas, fixtures, or documentation sources, update the documentation by running yarn run docgen.
FAQs
Deprecated - consider migrating to xrpl.js: https://xrpl.org/xrpljs2-migration-guide.html
The npm package rippel-lib receives a total of 31 weekly downloads. As such, rippel-lib popularity was classified as not popular.
We found that rippel-lib demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Rust’s crates.io team is advancing an RFC to add a Security tab that surfaces RustSec vulnerability and unsoundness advisories directly on crate pages.

Security News
/Research
Socket found a Rust typosquat (finch-rust) that loads sha-rust to steal credentials, using impersonation and an unpinned dependency to auto-deliver updates.

Research
/Security Fundamentals
A pair of typosquatted Go packages posing as Google’s UUID library quietly turn helper functions into encrypted exfiltration channels to a paste site, putting developer and CI data at risk.