
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
github.com/Excoriate/daggerverse/module-template
A simple Dagger place the description of the module here
Through the Dagger CLI, or by using it directly within your module, you can configure the following options:
ctr
: The container to use as a base container. If not specified, a new container is created.version
: The version of the Go image to use. Defaults to latest
.image
: The Go image to use. Defaults to golang:alpine
.{{.module_name_pkg}} // main module
├── .gitattributes
├── .gitignore
├── LICENSE
├── README.md
├── apis.go
├── cloud.go
├── commands.go
├── common.go
├── config.go
├── dagger.json
├── examples // Sub modules that represent examples of the module's functions with each SDK
│ └── go
│ ├── .gitattributes
│ ├── .gitignore
│ ├── dagger.json
│ ├── go.mod
│ ├── go.sum
│ ├── main.go
│ └── testdata
│ └── common
│ ├── README.md
│ └── test-file.yml
├── go.mod
├── go.sum
├── main.go
└── tests // Sub module that represent tests of the module's functions
├── .gitattributes
├── .gitignore
├── dagger.json
├── go.mod
├── go.sum
├── main.go
└── testdata
└── common
├── README.md
└── test-file.yml
NOTE: This structure comes out of the box if it's generated through Daggy. Just run
just create <module-name>
and you'll get the structure.
Command or functionality | Command | Example | Status |
---|---|---|---|
Add your feature here | run | dagger call <my function> | ✅ |
Place the description of the module here
List all the functions available in the module:
# enter into the module's directory
cd module-template
# list all the functions available in the module
dagger develop && dagger functions
Call a function:
# call a function
# dagger call <function-name> [arguments]
dagger call github.com/excoriate/daggerverse/module-template@version <function-name> [arguments]
This module includes a testing module that aims to test the functionality of the ModuleTemplate module. The tests are written in Go and can be run using the following command:
## Run the tests using the just command
just test module-template
If you'd like to contribute, mostly we use Just to automate tasks and Nix to manage the development environment. You can use the following commands to get started:
# initialize the pre-commit hooks
just init
# run CI or common things locally
just golint module-template
# run the tests
just test module-template
# Run the entire CI tasks locally
just cilocal module-template
Additionally, this module brings a new Daggerverse functionality that allows to automatically generate the module's documentation using an special (sub) module called {{.module_name_pkg}}/examples/sdk. This module contains a set of examples hat demonstrate how to use the module's functions.
To generate the documentation
It's important to notice that each example function in order to be rendered in the documentation, it must be preprocessed by module's name, in this case (camelCase) module-template
.
NOTE: The
just
command entails the use of the Justfile for task automation. If you don't have it, don't worry, you just need Nix to run the tasks using thedev-shell
built-in command:nix develop --impure --extra-experimental-features nix-command --extra-experimental-features flakes
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.