Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Kaskada's timestreams
library makes it easy to work with structured event-based data.
Define temporal queries on event-based data loaded from Python, using Pandas or PyArrow and push new data in as it occurs.
Or, execute the queries directly on events in your data lake and/or as they arrive on a stream.
With Kaskada you can unleash the value of real-time, temporal queries without the complexity of "big" infrastructure components like a distributed stream or stream processing system.
Under the hood, timestreams
is an efficient temporal query engine built in Rust.
It is built on Apache Arrow, using the same columnar execution strategy that makes ...
Use pyenv
and install at least 3.8
(most development occurs under 3.11
).
If multiple versions are installed, nox
will test against each of them.
To build this package, first install maturin
:
poetry shell
poetry install --no-root
maturin develop
pytest
Alternatively, install nox and run the tests inside an isolated environment:
nox
Install quarto-cli
on your machine. Also consider installing an IDE extension.
Generate reference docs
nox -s docs-gen
You should re-run this after making any updates to the pysrc
docstrings.
If Preview Docs is running in another shell, the system should auto-refresh with your changes.
Preview docs (with auto-refresh on edit)
nox -s docs
Cleanup generated and cached docs
nox -s docs-clean
Try this if you see something unexpected (especially after deleting or renaming).
Builds docs to docs/_site
nox -s docs-build
This is primarily used in CI.
FAQs
Kaskada query builder and local execution engine.
We found that kaskada demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.