
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
github.com/leanlabsio/kanban
Minimum Install Requrements:
OS: kernel minimum 3.10 (centOS 7, Ubuntu 14.04)
Packages: git, curl
sudo yum -y install git, curl
The easiest way to deploy Leanlabs Kanban board is to use docker-compose. Install instructions here. Assuming you have installed Docker and docker-compose.
git clone https://gitlab.com/leanlabsio/kanban.git
cd kanban
Go to https://gitlab.com/profile/applications or your GitLab installation and register your application to get the application client ID and client secret key required for OAuth.
Where
Redirect url http[s]://{KANBAN_SERVER_HOSTNAME}/assets/html/user/views/oauth.html
Where
KANBAN_SERVER_HOSTNAME
| http[s]://{KANBAN_SERVER_HOSTNAME} - URL on which LeanLabs Kanban will be reachable [same as redirect url with out /assets/html...], required
KANBAN_SECURITY_SECRET
| Change this string to antyhing you like. This string is used to generate user auth tokens
KANBAN_GITLAB_URL
| http[s]://{gitlab.example.com:port} - Your GitLab host URL, required
KANBAN_GITLAB_CLIENT
| Your GitLab OAuth client application ID, required for OAuth to work. Git this from your gitlab server.
KANBAN_GITLAB_SECRET
| Your GitLab OAuth client secret key, required for OAuth to work. Git this from your gitlab server.
KANBAN_ENABLE_SIGNUP
| Wheter to enable sign up with user API token.
Then
docker-compose up -d
If you followed instructions from "Installation with Docker", then the easiest way to upgrade would be:
git pull
docker-compose up -d
You can view the changelog here
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.