
Research
/Security News
DuckDB npm Account Compromised in Continuing Supply Chain Attack
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
Get hip or die trying
slng
is on npm! Check out out here
npm install -g slng
Once installed, you should be able to call with:
slng <search string>
slng will return (up to) the first 3 results by default. ability to change number of results coming soon
slng -R
slng --random
When passing the random flag, slng will search a random word and return (up to) the first 3 results by default. ability to change number of results coming soon
NOTE Random flag does not work if you pass a phrase; meaning that slng will search for the phrase.
e.g. slng -R gucci
and slng --random gucci
will return the results for 'gucci'.
If you see an issue with slng, feel free to create an issue for review. If we can reproduce the issue, we'll flag the ticket. Check out the rest of our contributing guidelines for more information.
FAQs
Get hip or die trying
We found that slng demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
Security News
The MCP Steering Committee has launched the official MCP Registry in preview, a central hub for discovering and publishing MCP servers.
Product
Socket’s new Pull Request Stories give security teams clear visibility into dependency risks and outcomes across scanned pull requests.