Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
github.com/mongodb/mongodb-kubernetes-operator
This is a Kubernetes Operator which deploys MongoDB Community into Kubernetes clusters.
If you are a MongoDB Enterprise customer, or need Enterprise features such as Backup, you can use the MongoDB Enterprise Operator for Kubernetes.
Here is a talk from MongoDB Live 2020 about the Community Operator:
Note
Hi, I'm Dan Mckean 👋 I'm the Product Manager for MongoDB's support of Kubernetes.
The Community Operator is something I inherited when I started, but it doesn't get as much attention from us as we'd like, and we're trying to understand how it's used in order to establish it's future. It will help us establish exactly what level of support we can offer, and what sort of timeframe we aim to provide support in 🙂
Here's a super short survey (it's much easier for us to review all the feedback that way!): https://docs.google.com/forms/d/e/1FAIpQLSfwrwyxBSlUyJ6AmC-eYlgW_3JEdfA48SB2i5--_WpiynMW2w/viewform?usp=sf_link
If you'd rather email me instead: dan.mckean@mongodb.com
See the documentation to learn how to:
NOTE: MongoDB Enterprise Kubernetes Operator docs are for the enterprise operator use case and NOT for the community operator. In addition to the docs mentioned above, you can refer to this blog post as well to learn more about community operator deployment
The MongoDB Community Kubernetes Operator supports the following features:
status
fieldBefore you contribute to the MongoDB Community Kubernetes Operator, please read:
Please file issues before filing PRs. For PRs to be accepted, contributors must sign our CLA.
Reviewers, please ensure that the CLA has been signed by referring to the contributors tool (internal link).
This project uses the following linters upon every Pull Request:
gosec
is a tool that find security problems in the codeBlack
is a tool that verifies if Python code is properly formattedMyPy
is a Static Type Checker for PythonKube-linter
is a tool that verified if all Kubernetes YAML manifests are formatted correctlyGo vet
A built-in Go static checkerSnyk
The vulnerability scannerPlease see the LICENSE file.
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.