Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@enhance/arc-plugin-posse
Advanced tools
Publish (on your) Own Site, Syndicate Elsewhere plugin for Enhance applications.
npm i @enhance/arc-plugin-posse
Add the following to your Architect project manifest (usually .arc):
@plugins
enhance/arc-plugin-posse
@posse
feed "https://url.to/rss"
The following higher-level settings are available in your Architect project manifest with the @posse
settings pragma:
feed
- the RSS feed to pull your posts from.rate
- how frequently to poll the feed
for new posts to syndicate. Default value is 1 day
. Accepts any valid rate expression.since
- the day in which to start checking your feed
for new posts. Defaults to today's date. Uses the data format YYYY-MM-DD
which is the only correct date format.Example:
@posse
feed "https://bookrecs.org/rss"
rate "1 day"
since "2023-04-02"
In order to enable Bluesky syndication the user will need to set two environment variables in their app, BLUESKY_USERNAME
and BLUESKY_PASSWORD
.
BLUESKY_USERNAME
- your Bluesky username without the leading @
symbol.BLUESKY_PASSWORD
- the password for your Bluesky account.Once you set these two environment variables you will need to deploy your application again for them to be read properly.
Then when a new posts is detected it will be syndicated to Bluesky following the format:
Item Title
Item Description
Item Link
In order to enable Dev.to syndication the user will need to set one environment variables in your app, DEV_TO_API_KEY
.
DEV_TO_API_KEY
- visit https://dev.to/settings/extensions. In the "DEV API Keys" section create a new key by adding a description and clicking on "Generate API Key"Once you set this environment variable you will need to deploy your application again for them to be read properly.
Then when a new posts is detected it will be syndicated to Dev.to. The plugin will convert your RSS feed item to Dev.to compatible markdown.
In order to enable Mastodon syndication the user will need to set two environment variables in their app, MASTODON_TOKEN
and MASTODON_URL
.
MASTODON_TOKEN
- Go to your settings page, open Development, and click the New Application button to create your personal access token.MASTODON_URL
- the url of your Mastodon server. For example: https://fosstodon.org/
Once you set these two environment variables you will need to deploy your application again for them to be read properly.
Then when a new posts is detected it will be syndicated to Mastodon following the format:
Item Title
Item Description
Item Link
Support for Twitter (X) is deprecated.
In order to enable Twitter syndication the user will need to set four environment variables in their app, TWITTER_API_KEY
, TWITTER_API_SECRET
, TWITTER_ACCESS_TOKEN
and TWITTER_ACCESS_TOKEN_SECRET
.
TWITTER_API_KEY
- This is the API Key under Consumer Keys in your app on developer.twitter.com.TWITTER_API_SECRET
- This is the API Secret under Consumer Keys in your app on developer.twitter.comTWITTER_ACCESS_TOKEN
- This is the Access Token under Authentication Tokens in your app on developer.twitter.com.TWITTER_ACCESS_TOKEN_SECRET
- This is the Access Token under Authentication Tokens in your app on developer.twitter.comto generate the TWITTER_ACCESS_TOKEN
and TWITTER_ACCESS_TOKEN_SECRET
you need to jump through a few hoops (as of this writing).
Settings
tab of your app under User authentication settings
click edit.App Permissions
to Read and write and Direct message
.Type of App
to Web App, Automated App or Bot
.App Info
.Keys and tokens
tab of your app click Regenerate
next to Access Token and Secret
.Once you set these four environment variables you will need to deploy your application again for them to be read properly.
Then when a new posts is detected it will be syndicated to Twitter following the format:
Item Title
Item Description
Item Link
FAQs
Enhance/Architect plugin for syndicating everywhere
The npm package @enhance/arc-plugin-posse receives a total of 3 weekly downloads. As such, @enhance/arc-plugin-posse popularity was classified as not popular.
We found that @enhance/arc-plugin-posse demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.