
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@itwin/connector-framework
Advanced tools
The @itwin/connector-framework package contains the classes which comprise the framework necessary to author iModel Connectors. In previous versions <= 2.x of the iTwin.js (iModel.js) SDK, it was included as part of the monorepo under IModelBridge. Going forward it will be a separate repository.
The main branch used for 2.x, based on iTwin.js 4.x, will be the default location for all fixes and enhancements. Patches will only be back-ported to 1.x if they are considered critical or related to security.
Version 1.x of the connector framework will be supported as long as iTwin.js 3.x is supported. Please refer to the iTwin.js API deprecation policy.
You may want to run the integration test and see the results hosted on the iModelHub. This is possible by setting a few environment variables to specify private/confidential parameters such as iTwin (project) id and iModel id, an AuthClient id, and user name and password.
An example .env file may look like ...
test_client_id=<client id here in quotes>
test_redirect_uri=<uri here in quotes>
test_scopes="imodels:modify imodels:read itwin-platform"
test_user_name=<valid email here in quotes>
test_user_password=<password corresponding>
# leave imjs_url_prefix undefined(or comment out) for prod
imjs_url_prefix = "qa-"
# if you optionally wish to authenticate with a callback URL and
# bypass the default authentication for the Integration tests,
# you can specify test_callbackUrl
# test_callbackUrl=<url goes here>
The word "itwin" replaces "imodel" and "connector" replaces "bridge".
TypeScript source files should import the new classes from @itwin/connector-framework.
e.g.
import { BaseConnector } from "@itwin/connector-framework";
package.json should include a dependency for @itwin/connector-framework
{
"dependencies": {
"@itwin/connector-framework": "latest"
}
}
The following scopes are required: imodels:modify imodels:read
NPM version 7.X and up is recommended. If you are using a lower version, you will have to manually install Peer Dependencies.
For any PR with changes beyond something exceedingly minor, an update changelog will be required for a pull request. This changelog can be added to CHANGELOG.md manually in a similar format to what is already there.
FAQs
iTwin Connector Framework
We found that @itwin/connector-framework demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.