Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
trytond-stock-package-shipping
Advanced tools
The package shipping module of the Tryton application platform.
Stock Package Shipping Module #############################
This module is the base module required to interact with shipping service providers.
Carrier
The Carrier model adds the following field:
This field is programmatically filled by the modules providing support for shipping companies.
Package Type
The Package Type model has been added the following fields:
Package
The Package model has been added the following fields:
Shipment Out
The Shipment Out model will check once in the Packed state if the shipment is a
valid shipment for the shipping service. He does that by calling a method that
is by convention named validate_packing_<shipping service>
.
Once a shipment is packed, the user can create the shipping for each packages
with the shipping service by clicking on the Create Shipping button. This
button triggers a wizard that is overridden in shipping service specific
modules. The starting state of the wizard is a StateTransition
. Its linked
method is overridden in shipping service modules in order to communicate with
the service.
FAQs
The package shipping module of the Tryton application platform.
We found that trytond-stock-package-shipping demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.