Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Please do not publicize this repository in any way. There are a few known documentation gaps and other issues we wish to address before publication. Thank you for your patience.
var tandem = new Tandem.Client('http://localhost:8008');
var file = tandem.open(fileId);
file.on('file-update', function(delta) {
// ...
});
file.update(delta);
var Tandem = require('tandem')
var server = require('http').Server();
new Tandem.Server(server);
Add to package.json
"dependencies" : {
"tandem": "0.12.x"
}
We use mocha as our testing framework. To run the unit tests, simply:
make test
To run our coverage tool:
make cov
The tandem source code is in the src folder. Tests are in the tests folder.
All other files/directories are just supporting npm, build, demo, or documentation files.
build - build output
demo - demos
doc - additional documentation
scripts - test coverage script
src - source code
tests - unit tests
browser.js - npm
client.coffee - enable node.js to require src/client, used by unit tests
Gruntfile.coffee - grunt configs
index.js - npm
Makefile - define make commands
package.json - npm
FAQs
WARNING ===
We found that tandem demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.