Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
从函数签名和文档字符串中提取函数参数信息,并生成对应的GUI控件。
pip install function2widgets
本项目是PyGUIAdapter 项目的基础设施而开发,但也可以作为一个单独的项目用于其他目的。
本项目的使用可以参考:examples。该目录下有详细的使用示例。
其中,综合的示例代码可以参考:examples/comprehensive下的示例代码。
0.5.6
版本以后,本项目经历了一次整体重构,代码组织方式、一些命名、函数接口等均有较大变化,请从代码示例或源码中查看详细用法。FAQs
Unknown package
We found that function2widgets demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.