
Security News
Crates.io Users Targeted by Phishing Emails
The Rust Security Response WG is warning of phishing emails from rustfoundation.dev targeting crates.io users.
@aredridel/cgm-plugin-dexcom-share
Advanced tools
Fetches data from Dexcom's webservice and emits it as posted messages
This plugin fetches data from dexcom share and relays it so the cgm can integrate it.
The bridge periodically queries Dexcom's Share web services for new CGM data.
VARIABLE (default) - description
DEXCOM_ACCOUNT_NAME - Your Dexcom Share2 usernameDEXCOM_PASSWORD - Your Dexcom Share2 passwordmaxCount (1) - The maximum number of records to fetch per updateminutes (1440) - The time window to search for new data per update (default is one day in minutes)firstFetchCount (3) - Changes maxCount during the very first update only.maxFailures (3) - The program will stop running after this many
consecutively failed login attempts with a clear error message in the logs.SHARE_INTERVAL (150000) - The time to wait between each update (default is 2.5 minutes in milliseconds)NS - A fully-qualified Nightscout URL (e.g. https://sitename.herokuapp.com) which overrides WEBSITE_HOSTNAMEAPI_SECRET, DEXCOM_ACCOUNT_NAME and DEXCOM_PASSWORD in Connection Strings.WEBSITE_HOSTNAME because the value is obtained from the existing [Azure website environment][azure-environment].[As described by Scott Hanselman][blog-post], the bridge logs in to Dexcom
Share as the data publisher. It re-uses the token every 5 minutes to fetch
the maxCount latest glucose records within the last specified minutes.
This information is then sent to the user's specified Nightscout install,
making the data available to the beloved pebble watch and other equipment owned
and operated by the receiver's owner. It will continue to re-use the same
sessionID until it expires, at which point it should attempt to log in again.
If it can log in again, it will continue to re-use the new token to fetch data,
storing it into Nightscout.
This project is not FDA approved, not recommended for therapy, and not recommended by [Dexcom][dexcom-eula].
FAQs
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Rust Security Response WG is warning of phishing emails from rustfoundation.dev targeting crates.io users.

Product
Socket now lets you customize pull request alert headers, helping security teams share clear guidance right in PRs to speed reviews and reduce back-and-forth.

Product
Socket's Rust support is moving to Beta: all users can scan Cargo projects and generate SBOMs, including Cargo.toml-only crates, with Rust-aware supply chain checks.