
Research
/Security News
DuckDB npm Account Compromised in Continuing Supply Chain Attack
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
WARNING: CookieCutter is very early in its development cycle (pre-alpha).
CookieCutter provides a nice DSL for defining your cookies so that you can formalize your cookie definitions. This leads to DRY-er code by ensuring that concerns such as the domain and lifetime of a cookie are consistent. It also makes it easy to know what info you are putting into your cookies, which is becoming more important these days as more laws surrounding cookies get written.
Add this line to your application's Gemfile:
gem 'cookie_cutter'
And then execute:
$ bundle
Or install it yourself as:
$ gem install cookie_cutter
class MyCookie < CookieCutter::Base
store_as :my
domain :all
is_permanent
secure_requests_only
http_only
has_attribute :language
has_attribute :country
end
#writes your cookie
cookie = MyCookie.find(request)
cookie.language = "fr"
#reads your cookie
cookie = MyCookie.find(request)
puts "My language is #{cookie.language}"
git checkout -b my-new-feature
)git commit -am 'Added some feature'
)git push origin my-new-feature
)FAQs
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
Security News
The MCP Steering Committee has launched the official MCP Registry in preview, a central hub for discovering and publishing MCP servers.
Product
Socket’s new Pull Request Stories give security teams clear visibility into dependency risks and outcomes across scanned pull requests.