
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
v8r is a command-line validator that uses Schema Store to detect a suitable schema for your input files based on the filename.
š¦ Install the package from NPM
š Jump into the Documentation to get started
š¦ 5.0.0 - 2025-05-10
Following on from the deprecations in version 4.4.0, version 5.0.0 contains a number of breaking changes:
--format
CLI argument and format
config file key have been removed.
Switch to using --output-format
and outputFormat
..gitignore
by default.fileLocation
argument of getSingleResultLogMessage
has been removed.
The signature is now getSingleResultLogMessage(result, format)
.
Plugins implementing the getSingleResultLogMessage
hook will need to to update
the signature.
If you are using fileLocation
in the getSingleResultLogMessage
function body,
switch to using result.fileLocation
.getSingleResultLogMessage
, getAllResultsLogMessage
and parseInputFile
plugin hooks may need to be updated.Other changes in this release:
FAQs
A command-line JSON, YAML and TOML validator that's on your wavelength
The npm package v8r receives a total of 1,473 weekly downloads. As such, v8r popularity was classified as popular.
We found that v8r demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago.Ā It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.