Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
scrilla is an open-source financial analysis application written in Python. It can optimize portfolios, calculate statistics using a variety of methods and algorithms, generate graphical plots and much more. It uses historical data retrieved from various sources, such as the US Treasury RSS Feed, AlphaVantage, IEX and Quandl, to calibrate models.
NOTE: None of the results of scrilla should be interpretted as financial advice. All results assume past trends will continue indefinitely into the future, which is usually never the case in reality.
Branch | Status |
---|---|
pypi/micro-update | |
pypi/micro-update | |
develop/main |
Refer to the documentation for more detailed information on installation and usage.
Install the package with the Python package manager,
pip install scrilla
This will install a command line interface on your path under the name scrilla
. Confirm your installation with with the version
command,
scrilla version
You may need to add your Python scripts /bin/ to the $PATH if this command is not found.
To keep the installation as minimal as possible, the base package does not include the GUI libraries. You can install the optional GUI dependency (PySide6) with,
pip install scrilla[gui]
Note, the GUI has a different CLI entrypoint, namely,
scrilla-gui
If you are developing, you can build from source. git clone
the repository and then from the root directory install the project dependencies and build the library,
pip3 install -r requirements.txt
python3 -m build
cd
into the generated /dist/ to manually install the packaged code,
pip install scrilla-<major>.<minor>.<micro>-py3-none-any.whl
In order to use this application, you will need to register for API keys with AlphaVantage, IEX and Quandl/Nasdaq. The program will need to be made aware of these keys somehow. The best option is storing these credentials in environment variables. You can add the following lines to your .bashrc profile or corresponding configuration file for whatever shell you are using,
export ALPHA_VANTAGE_KEY=<key goes here>
export QUANDL_KEY=<key goes here>
export IEX_KEY=<key goes here>
You can also invoke the CLI function store
to store the credentials in the local installation /data/common/ directory. To do so,
scrilla store -key <key> -value <value>
where <key>
is one of the values: ALPHA_VANTAGE_KEY, QUANDL_KEY or IEX_KEY. <value>
is the corresponding key itself given to you after registration. Obviously, <value>
is case-sensitive
Keep in mind if using this method to store the API keys, the keys will be stored unencrypted in the local installation's /data/common/ directory. The recommended method is storing the credentials in the environment.
If no API keys are found through either of these methods, the application will raise an exception.
NOTE: The Quandl/Nasdaq key is technically no required for the majority of the application to function, as interest rates are now retrieved directly from the US Treasury RSS feed. However, it is still recommended that you register for an API key, as Quandl/Nasdaq is still the only source of economic statistics, like GDP or inflation rates.
A sample environment file has been included in /env/.sample.env. To configure the application environment, copy this file into a new environment, adjust the values and load it into your session,
cp ./env/.sample.env ./env/.env
# adjust .env values
source ./env/.env
# the values loaded into your session will now configure scrilla's execution environment
scrilla risk-profile GD LMT
The following command will optimize a portfolio of consisting of ALLY, BX, GLD, BTC and ETH over the specified date range and save the result to a JSON file,
scrilla optimize-portfolio ALLY BX GLD BTC ETH \
-start <YYYY-MM-DD> \
-end <YYYY-MM-DD> \
-save <absolute path to json file>
The following command will calculaate the efficient frontier for a portfolio consisting of SPY, GLD and USO over the specified date range and save the result to a JSON file,
scrilla efficient-frontier SPY GLD USO \
--start <YYYY-MM-DD> \
--end <YYYY-MM-DD> \
--save <absolute path to json file>
The following command will generate a plot of this frontier in the return-volatility plane,
scrilla plot-ef SPY GLD USO \
--start <YYYY-MM-DD> \
--end <YYYY-MM-DD>
scrilla has lots of other functions. See usage for more information.
TODO
currently working on a DynamoDB-based cache and Dockerfiles for lambda functions wrapped around scrilla's main features. will update this section once everything is completed.
FAQs
a financial optimization program
We found that scrilla demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.