
Security News
Critical Security Vulnerability in React Server Components
React disclosed a CVSS 10.0 RCE in React Server Components and is advising users to upgrade affected packages and frameworks to patched versions now.
@cumulus/deployment
Advanced tools
@cumulus/deployment includes cloudformation templates needed for a successful deployment of a Cumulus Instance. The templates can be used with kes, a node CLI helper for AWS CloudFormation.
Cumulus is a cloud-based data ingest, archive, distribution and management prototype for NASA's future Earth science data streams.
See the Cumulus deployment documentation for a detailed overview of how to deploy Cumulus.
To make a contribution, please see our contributing guidelines.
[v1.21.0] 2020-03-30
messageConsumer for sns and kinesis-type rules now fetches
the collection information from the message. You should ensure that your rule's collection
name and version match what is in the message for these ingest messages to be processed.
If no matching rule is found, an error will be thrown and logged in the
messageConsumer Lambda function's log group.CUMULUS-1629`
PrivateApiLambda() which is configured to not require authentication. This Lambda is not connected to an API gateway@cumulus/api-client with functions for use by workflow lambdas to call the API when neededCUMULUS-1732
PythonReferenceSpec) to test cumulus-message-adapter-pythonand cumulus-process-py integration.CUMULUS-1795
deploy_to_ngap flag is truemessageConsumer for sns and kinesis-type rules now fetches the collection
information from the message.granulesApi, rulesApi, emsApi, executionsAPI from @cumulus/integration-test/api in favor of code moved to @cumulus/api-client@cumulus/api/models/Granule.createGranulesFromSns()@cumulus/api/models/Granule.removeGranuleFromCmr()@cumulus/common/aws:
apigateway()buildS3Uri()calculateS3ObjectChecksum()cf()cloudwatch()cloudwatchevents()cloudwatchlogs()createAndWaitForDynamoDbTable()createQueue()deleteSQSMessage()describeCfStackResources()downloadS3File()downloadS3Files()DynamoDbSearchQueue classdynamodbstreams()ec2()ecs()fileExists()findResourceArn()fromSfnExecutionName()getFileBucketAndKey()getJsonS3Object()getQueueUrl()getObjectSize()getS3ObjectReadStream()getSecretString()getStateMachineArn()headObject()isThrottlingException()kinesis()lambda()listS3Objects()promiseS3Upload()publishSnsMessage()putJsonS3Object()receiveSQSMessages()s3CopyObject()s3GetObjectTagging()s3Join()S3ListObjectsV2Queue classs3TagSetToQueryString()s3PutObjectTagging()secretsManager()sendSQSMessage()sfn()sns()sqs()sqsQueueExists()toSfnExecutionName()uploadS3FileStream()uploadS3Files()validateS3ObjectChecksum()@cumulus/common/CloudFormationGateway class@cumulus/common/concurrency/Mutex class@cumulus/common/errors@cumulus/common/sftp@cumulus/common/string.unicodeEscape@cumulus/cmrjs/cmr-utils.getGranuleId()@cumulus/cmrjs/cmr-utils.getCmrFiles()@cumulus/cmrjs/cmr/CMR class@cumulus/cmrjs/cmr/CMRSearchConceptQueue class@cumulus/cmrjs/utils.getHost()@cumulus/cmrjs/utils.getIp()@cumulus/cmrjs/utils.hostId()@cumulus/cmrjs/utils/ummVersion()@cumulus/cmrjs/utils.updateToken()@cumulus/cmrjs/utils.validateUMMG()@cumulus/ingest/aws.getEndpoint()@cumulus/ingest/aws.getExecutionUrl()@cumulus/ingest/aws/invoke()@cumulus/ingest/aws/CloudWatch class@cumulus/ingest/aws/ECS class@cumulus/ingest/aws/Events class@cumulus/ingest/aws/SQS class@cumulus/ingest/aws/StepFunction class@cumulus/ingest/util.normalizeProviderPath()@cumulus/integration-tests/index.listCollections()@cumulus/integration-tests/index.listProviders()@cumulus/integration-tests/index.rulesList()@cumulus/integration-tests/api/api.addCollectionApi()FAQs
Deployment templates for cumulus
We found that @cumulus/deployment demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 8 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
React disclosed a CVSS 10.0 RCE in React Server Components and is advising users to upgrade affected packages and frameworks to patched versions now.

Research
/Security News
We spotted a wave of auto-generated “elf-*” npm packages published every two minutes from new accounts, with simple malware variants and early takedowns underway.

Research
/Security News
Malicious Rust crate evm-units disguised as an EVM version helper downloads and silently executes OS-specific payloads likely aimed at crypto theft.