Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Pure-Python data structure for working with Ed25519 (and Ristretto) field elements and operations.
Pure-Python data structure for working with Ed25519 (and Ristretto) field elements and operations.
|pypi| |readthedocs| |actions| |coveralls|
.. |pypi| image:: https://badge.fury.io/py/fe25519.svg :target: https://badge.fury.io/py/fe25519 :alt: PyPI version and link.
.. |readthedocs| image:: https://readthedocs.org/projects/fe25519/badge/?version=latest :target: https://fe25519.readthedocs.io/en/latest/?badge=latest :alt: Read the Docs documentation status.
.. |actions| image:: https://github.com/nthparty/fe25519/workflows/lint-test-cover-docs/badge.svg :target: https://github.com/nthparty/fe25519/actions/workflows/lint-test-cover-docs.yml :alt: GitHub Actions status.
.. |coveralls| image:: https://coveralls.io/repos/github/nthparty/fe25519/badge.svg?branch=main :target: https://coveralls.io/github/nthparty/fe25519?branch=main :alt: Coveralls test coverage summary.
This library provides a native Python implementation of Ed25519 <https://ed25519.cr.yp.to>
__ field elements and a number of operations over them. The library makes it possible to fill gaps in application prototypes that may have specific limitations with respect to their operating environment or their ability to rely on non-Python dependencies.
The implementation is based upon and is compatible with the corresponding implementation of Ed25519 and Ristretto field elements used in libsodium <https://github.com/jedisct1/libsodium>
. For more information and background about the underlying mathematical structures and primitives, consult materials about Curve25519 <https://cr.yp.to/ecdh.html>
, the Ristretto <https://ristretto.group>
__ group, and the related Ed25519 <https://ed25519.cr.yp.to>
__ system.
This library is available as a package on PyPI <https://pypi.org/project/fe25519>
__:
.. code-block:: bash
python -m pip install fe25519
The library can be imported in the usual ways:
.. code-block:: python
import fe25519
from fe25519 import fe25519
All installation and development dependencies are fully specified in pyproject.toml
. The project.optional-dependencies
object is used to specify optional requirements <https://peps.python.org/pep-0621>
__ for various development tasks. This makes it possible to specify additional options (such as docs
, lint
, and so on) when performing installation using pip <https://pypi.org/project/pip>
__:
.. code-block:: bash
python -m pip install .[docs,lint]
Documentation
^^^^^^^^^^^^^
The documentation can be generated automatically from the source files using Sphinx <https://www.sphinx-doc.org>
__:
.. code-block:: bash
python -m pip install .[docs]
cd docs
sphinx-apidoc -f -E --templatedir=_templates -o _source .. && make html
Testing and Conventions
^^^^^^^^^^^^^^^^^^^^^^^
All unit tests are executed and their coverage is measured when using pytest <https://docs.pytest.org>
__ (see the pyproject.toml
file for configuration details):
.. code-block:: bash
python -m pip install .[test]
python -m pytest
Concise unit tests are implemented with the help of fountains <https://pypi.org/project/fountains>
__; new reference specifications for these tests can be generated by running the testing module directly:
.. code-block:: bash
python test/test_fe25519.py
Style conventions are enforced using Pylint <https://pylint.readthedocs.io>
__:
.. code-block:: bash
python -m pip install .[lint]
python -m pylint src/fe25519 test/test_fe25519.py
Contributions
^^^^^^^^^^^^^
In order to contribute to the source code, open an issue or submit a pull request on the GitHub page <https://github.com/nthparty/fe25519>
__ for this library.
Versioning
^^^^^^^^^^
Beginning with version 0.1.0, the version number format for this library and the changes to the library associated with version number increments conform with Semantic Versioning 2.0.0 <https://semver.org/#semantic-versioning-200>
__.
Publishing
^^^^^^^^^^
This library can be published as a package on PyPI <https://pypi.org/project/fe25519>
__ by a package maintainer. First, install the dependencies required for packaging and publishing:
.. code-block:: bash
python -m pip install .[publish]
Ensure that the correct version number appears in pyproject.toml
, and that any links in this README document to the Read the Docs documentation of this package (or its dependencies) have appropriate version numbers. Also ensure that the Read the Docs project for this library has an automation rule <https://docs.readthedocs.io/en/stable/automation-rules.html>
__ that activates and sets as the default all tagged versions. Create and push a tag for this version (replacing ?.?.?
with the version number):
.. code-block:: bash
git tag ?.?.?
git push origin ?.?.?
Remove any old build/distribution files. Then, package the source into a distribution archive:
.. code-block:: bash
rm -rf build dist src/*.egg-info
python -m build --sdist --wheel .
Finally, upload the package distribution archive to PyPI <https://pypi.org>
__:
.. code-block:: bash
python -m twine upload dist/*
FAQs
Pure-Python data structure for working with Ed25519 (and Ristretto) field elements and operations.
We found that fe25519 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.