
Research
Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.
open-cluster-management.io/governance-policy-status-sync
Advanced tools
The governance policy status sync runs on managed clusters, updating Policy statuses on both the hub and (local) managed clusters, based on events and changes in the managed cluster. This controller is a part of the governance-policy-framework.
This operator watches for the following changes to trigger a reconcile:
Every reconcile does the following things:
Go to the Contributing guide to learn how to get involved.
Check the Security guide if you need to report a security issue.
You will need kind installed.
make kind-bootstrap-cluster-dev
make build-images
make kind-deploy-controller-dev
make test-dependencies
make test
make e2e-dependencies
make e2e-test
make kind-delete-cluster
The deploy/operator.yaml file is generated via Kustomize. The deploy/rbac directory of
Kustomize files is managed by the operator-sdk and Kubebuilder using
markers. After updating the markers or
any of the Kustomize files, you may regenerate deploy/operator.yaml by running
make generate-operator-yaml.
governance-policy-status-sync is part of the open-cluster-management community. For more information, visit: open-cluster-management.io.FAQs
Unknown package
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.