Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
github.com/rancher/k3d
k3s is the lightweight Kubernetes distribution by Rancher: rancher/k3s
This repository is based on @zeerorg's zeerorg/k3s-in-docker, reimplemented in Go by @iwilltry42 in iwilltry42/k3d, which is now rancher/k3d.
You have several options there:
use the install script to grab the latest release:
wget -q -O - https://raw.githubusercontent.com/rancher/k3d/master/install.sh | bash
curl -s https://raw.githubusercontent.com/rancher/k3d/master/install.sh | bash
use the install script to grab a specific release (via TAG
environment variable):
wget -q -O - https://raw.githubusercontent.com/rancher/k3d/master/install.sh | TAG=v1.3.4 bash
curl -s https://raw.githubusercontent.com/rancher/k3d/master/install.sh | TAG=v1.3.4 bash
Use Homebrew: brew install k3d
(Homebrew is avaiable for MacOS and Linux)
Grab a release from the release tab and install it yourself.
Via go: go install github.com/rancher/k3d
(Note: this will give you unreleased/bleeding-edge changes)
or...
go get -u github.com/rancher/k3d
make build
to build for your current systemgo install
to install it to your GOPATH
(Note: this will give you unreleased/bleeding-edge changes)make build-cross
to build for all systemsCheck out what you can do via k3d help
Example Workflow: Create a new cluster and use it with kubectl
(Note: kubectl
is not part of k3d
, so you have to install it first if needed)
k3d create
to create a new single-node cluster (docker container)export KUBECONFIG=$(k3d get-kubeconfig)
to make kubectl
to use the kubeconfig for that clusterkubectl get pods --all-namespaces
k3d delete
to delete the default clusterIf you want to access your services from the outside (e.g. via Ingress), you need to map the ports (e.g. port 80 for Ingress) using the --publish
flag (or aliases).
Check out the examples here.
Find more details under the following Links:
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.