
Research
/Security News
10 npm Typosquatted Packages Deploy Multi-Stage Credential Harvester
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.
org.mvnpm.at.opentelemetry:instrumentation-pg
Advanced tools
OpenTelemetry instrumentation for `pg` and `pg-pool` database client for PostgreSQL
Getting Started • API Documentation • Contributing
A repository for community-maintained OpenTelemetry JavaScript contributions that are not part of the core repository and core distribution of the API and the SDK.
This project includes:
Instrumentations: OpenTelemetry can collect tracing data automatically using instrumentations. Vendors/Users can also create and use their own. Please read the contributing guidelines on adding new instrumentation before opening any PRs.
Resource Detectors: OpenTelemetry can collect resource attributes of the entity that producing telemetry. For example, a process producing telemetry that is running in a container on Kubernetes has a Pod name, it is in a namespace and possibly is part of a Deployment which also has a name. All three of these attributes can be included in the Resource.
This repository includes various components, each maintained by one or more designated component owners. Unless necessary to resolve disagreements, @open-telemetry/javascript-maintainers take a more passive role when it comes to Maintaining these components.
Component owners have the authority to make decisions on implementation and feature requests, following the best practices and the mission, vision and values of the OpenTelemetry Project. They are also assigned the Triager role to manage issues related to their components, and are the primary contact for conducting PR reviews for their components.
Component owners are automatically assigned to pull requests as reviewers. The source of truth for component ownership is .github/component_owners.yml.
Stability level for components in this repository follow the definitions in CONTRIBUTING.md.
Packages in this repository have a variable range of support for Node.JS and browser versions which for each package depend on
See the README.md files and the engines field in the package.json files for the respective packages for support information about that package.
See the support section in the core repository for more general information.
We'd love your help! Use tags up-for-grabs and good first issue to get started with the project. Follow CONTRIBUTING guide to report issues or submit a proposal.
Apache 2.0 - See LICENSE for more information.
FAQs
Unknown package
We found that org.mvnpm.at.opentelemetry:instrumentation-pg demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.

Product
Socket Firewall Enterprise is now available with flexible deployment, configurable policies, and expanded language support.

Security News
Open source dashboard CNAPulse tracks CVE Numbering Authorities’ publishing activity, highlighting trends and transparency across the CVE ecosystem.