
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
github.com/blakepettersson/gitops-engine
Various GitOps operators address different use-cases and provide different user experiences but all have similar set of core features. The team behind Argo CD has implemented a reusable library that implements core GitOps features:
Do you want to propose one more feature and want to enhance the existing one?
Proposals and ideas are in markdown docs in the specs/
directory.
To create a new proposal, simply copy the spec template
,
name the file corresponding to the title of your proposal, and place it in the
specs/
directory.
A good starting point to understand the structure is the GitOps Engine Design spec.
We tried to answer frequently asked question in a separate FAQ document.
This project is licensed under the Apache 2 license.
The GitOps Engine follows the CNCF Code of Conduct.
If you are as excited about GitOps and one common engine for it as much as we are, please get in touch. If you want to write code that's great, if you want to share feedback, ideas and use-cases, that's great too.
Find us on the #gitops channel on Kubernetes Slack (get an invite here).
At this stage we are interested in feedback, use-cases and help on the GitOps Engine.
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.