Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
python wrapper and metaschema for datadictionary. It can be used to:
Say you have a dictionary you are building locally and you want to see if it will pass the tests.
You can add a simple alias to your .bash_profile
to enable a quick test command:
testdict() { docker run --rm -v $(pwd):/dictionary quay.io/cdis/dictionaryutils:master; }
Then from the directory containing the gdcdictionary
directory run testdict
.
If you wish to generate fake simulated data you can also do that with dictionaryutils and the data-simulator.
simdata() { docker run --rm -v $(pwd):/dictionary -v $(pwd)/simdata:/simdata quay.io/cdis/dictionaryutils:master /bin/sh -c "cd /dictionary && python setup.py install --force; python /src/datasimulator/bin/data-simulator simulate --path /simdata/ $*; export SUCCESS=$?; rm -rf build dictionaryutils dist gdcdictionary.egg-info; chmod -R a+rwX /simdata; exit $SUCCESS"; }
simdataurl() { docker run --rm -v $(pwd):/dictionary -v $(pwd)/simdata:/simdata quay.io/cdis/dictionaryutils:master /bin/sh -c "python /src/datasimulator/bin/data-simulator simulate --path /simdata/ $*; chmod -R a+rwX /simdata"; }
Then from the directory containing the gdcdictionary
directory run simdata
and a folder will be created called simdata
with the results of the simulator run. You can also pass in additional arguments to the data-simulator script such as simdata --max_samples 10
.
The --max_samples
argument will define a default number of nodes to simulate, but you can override it using the --node_num_instances_file
argument. For example, if you create the following instances.json
:
{
"case": 100,
"demographic": 100
}
Then run the following:
docker run --rm -v $(pwd):/dictionary -v $(pwd)/simdata:/simdata quay.io/cdis/dictionaryutils:master /bin/sh -c "cd /dictionary && python setup.py install --force; python /src/datasimulator/bin/data-simulator simulate --path /simdata/ --program workshop --project project1 --max_samples 10 --node_num_instances_file instances.json; export SUCCESS=$?; rm -rf build dictionaryutils dist gdcdictionary.egg-info; chmod -R a+rwX /simdata; exit $SUCCESS";
Then you'll get 100 each of case
and demographic
nodes and 10 each of everything else. Note that the above example also defines program
and project
names.
You can also run the simulator for an arbitrary json url by using simdataurl --url https://datacommons.example.com/schema.json
.
from dictionaryutils import DataDictionary
dict_fetch_from_remote = DataDictionary(url=URL_FOR_THE_JSON)
dict_loaded_locally = DataDictionary(root_dir=PATH_TO_SCHEMA_DIR)
import json
from dictionaryutils import dump_schemas_from_dir
with open('dump.json', 'w') as f:
json.dump(dump_schemas_from_dir('../datadictionary/gdcdictionary/schemas/'), f)
FAQs
Python wrapper and metaschema for datadictionary.
We found that dictionaryutils demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.