Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
gopkg.in/libvirt/libvirt-go-xml.v5
Go API for manipulating libvirt XML documents
This package provides a Go API that defines a set of structs, annotated for use with "encoding/xml", that can represent libvirt XML documents. There is no dependancy on the libvirt library itself, so this can be used regardless of the way in which the application talks to libvirt.
The libvirt project aims to add support for new APIs to libvirt-go as soon as they are added to the main libvirt C library. If you are submitting changes to the libvirt C library API, please submit a libvirt-go change at the same time.
Bug fixes and other improvements to the libvirt-go library are welcome at any time. The preferred submission method is to use git send-email to submit patches to the libvir-list@redhat.com mailing list. eg. to send a single patch
# git send-email --to libvir-list@redhat.com --subject-prefix "PATCH go-xml" \
--smtp-server=$HOSTNAME -1
Or to send all patches on the current branch, against master
$ git send-email --to libvir-list@redhat.com --subject-prefix "PATCH go-xml" \
--smtp-server=$HOSTNAME --no-chain-reply-to --cover-letter --annotate \
master..
Note the master GIT repository is at
http://libvirt.org/git/?p=libvirt-go.git;a=summary
The following automatic read-only mirrors are available as a convenience to allow contributors to "fork" the repository:
https://gitlab.com/libvirt/libvirt-go
https://github.com/libvirt/libvirt-go
While you can send pull-requests to these mirrors, they will be re-submitted via emai to the mailing list for review before being merged, unless they are trivial/obvious bug fixes.
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.