Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
.. image:: https://travis-ci.org/dbcli/cli_helpers.svg?branch=master :target: https://travis-ci.org/dbcli/cli_helpers
.. image:: https://ci.appveyor.com/api/projects/status/37a1ri2nbcp237tr/branch/master?svg=true :target: https://ci.appveyor.com/project/dbcli/cli-helpers
.. image:: https://codecov.io/gh/dbcli/cli_helpers/branch/master/graph/badge.svg :target: https://codecov.io/gh/dbcli/cli_helpers
.. image:: https://img.shields.io/pypi/v/cli_helpers.svg?style=flat :target: https://pypi.python.org/pypi/cli_helpers
.. start-body
CLI Helpers is a Python package that makes it easy to perform common tasks when building command-line apps. It's a helper library for command-line interfaces.
Libraries like Click <http://click.pocoo.org/5/>
_ and
Python Prompt Toolkit <https://python-prompt-toolkit.readthedocs.io/en/latest/>
_
are amazing tools that help you create quality apps. CLI Helpers complements
these libraries by wrapping up common tasks in simple interfaces.
CLI Helpers is not focused on your app's design pattern or framework -- you can use it on its own or in combination with other libraries. It's lightweight and easy to extend.
What's included in CLI Helpers?
.. end-body
Read the documentation at http://cli-helpers.rtfd.io
FAQs
Helpers for building command-line apps
We found that cli-helpers demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.