
Research
5 Malicious Chrome Extensions Enable Session Hijacking in Enterprise HR and ERP Systems
Five coordinated Chrome extensions enable session hijacking and block security controls across enterprise HR and ERP platforms.
@architect/deploy
Advanced tools
@architect/deployArchitect serverless framework module for deploying applications to cloud infrastructure
npm i @architect/deploy
let deploy = require('@architect/deploy')
You need to have the sam command-line utility available on your $PATH. Check out AWS' docs for instructions on how to install this.
deploy.direct({ isDryRun, srcDirs }, callback)Deploys function code directly to one or more staging (or production) environment Lambdas by ommitting CloudFormation and directly updating code payloads. This is very useful for live debugging; changes made with direct deploys should be considered temporary.
deploy.sam({ quiet, verbose, production }, callback)Deploys all infrastructure associated to your @architect app.
Set quiet to truthy to suppress deployment progress and status messages (from the updater system). Set verbose to truthy to enable detailed output including CloudFormation logs, file operation details, and deployment artifact information. By default will only push to the staging environment unless production is truthy.
deploy.static({ bucket, credentials, fingerprint, prefix, prune, quiet, region, verbose, production }, callback)All parameters are optional.
Pushes static assets from the public/ folder of @architect apps to S3, as defined by your @architect app's .arc file. Respects fingerprint (true or external), prefix, prune, and ignore params or @static pragma directives (more information available on the @static arc guide).
By default will only publish to the staging environment unless production is truthy. Set verbose to truthy to enable chatty mode.
aws-sdk caveatDeploy requires aws-sdk; earlier versions included aws-sdk in peerDependencies, which prior to npm 7 would not automatically install aws-sdk. This is because Architect assumes you already have aws-sdk installed via Architect, or that it's available at runtime if you're using Deploy in a Lambda.
However, npm 7 (once again) changed the behavior of peerDependencies, now automatically installing all peerDependencies (instead of merely printing a reminder). This means any Lambdas that use Deploy would get a >50MB dependency payload if deployed on a machine with npm 7.
As such, please ensure aws-sdk is installed to your project or globally to your machine. We are sorry to make this a userland issue, but we feel this is preferable to unnecessarily and invisibly causing aws-sdk to be double-installed in Lambdas, negatively impacting coldstart times and adding to bug vectors.
FAQs
Deploys @architect projects
The npm package @architect/deploy receives a total of 1,560 weekly downloads. As such, @architect/deploy popularity was classified as popular.
We found that @architect/deploy demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Five coordinated Chrome extensions enable session hijacking and block security controls across enterprise HR and ERP platforms.

Research
Node.js patched a crash bug where AsyncLocalStorage could cause stack overflows to bypass error handlers and terminate production servers.

Research
/Security News
A malicious Chrome extension steals newly created MEXC API keys, exfiltrates them to Telegram, and enables full account takeover with trading and withdrawal rights.