Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Discord library built on discord.py to simplify source code by rendering templates of embeds and menus
Discord templating engine built on discord.py, to help separate text of embeds from the source code. Inspired by Flask.
Key Features:
Python3.8 or higher is required
To run the tests, run the following command in the root directory:
Windows:
python -m unittest tests -v
Linux:
python3 -m unittest tests -v
This is explained in more detail in the wiki
Wrap expressions that need to evaluated with {}
, such as {player.name}
or {todays_date}
Sample XML file:
<discord>
<message key="test_key">
<embed>
<title>Test</title>
<description>Test Description</description>
<colour>magenta</colour>
<timestamp format="%Y-%m-%d %H:%M:%S.%f">{todays_date}</timestamp>
<url>https://www.discord.com</url>
<fields>
<field>
<name>Test Field</name>
<value>Test Text</value>
</field>
</fields>
<footer>
<text>Test Footer</text>
<icon>https://cdn.discordapp.com/embed/avatars/0.png</icon>
</footer>
<thumbnail>https://cdn.discordapp.com/embed/avatars/0.png</thumbnail>
<image>https://cdn.discordapp.com/embed/avatars/0.png</image>
<author>
<name>Test Author</name>
<icon>https://cdn.discordapp.com/embed/avatars/0.png</icon>
<url>https://discordapp.com</url>
</author>
</embed>
<view>
<components>
<button key="understood_button">
<label>Understood</label>
<style>success</style>
</button>
</components>
</view>
</message>
</discord>
using the above xml file, for example, you can create an embed with the following code:
import datetime
from typing import Literal
import discord
from discord.ext import commands
import qalib
from qalib.template_engines import formatter
bot = commands.AutoShardedBot(command_prefix="!", intents=discord.Intents.all())
Messages = Literal["test_key"]
async def acknowledged(interaction: discord.Interaction):
await interaction.response.send_message("Acknowledged", ephemeral=True)
@bot.command()
@qalib.qalib_context(formatter.Formatter(), "templates/test.xml")
async def test(ctx: qalib.QalibContext[Messages]):
callables = {"understood_button": acknowledged}
await ctx.rendered_send("test_key", callables, keywords={
"todays_date": datetime.datetime.now()
})
FAQs
Discord library built on discord.py to simplify source code by rendering templates of embeds and menus
We found that discord-qalib demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.