Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@eotl/ui-inventory
Advanced tools
This is the web based user interface for Open
Inventory. It is currently a Vue2
app. It is automatically installed in Open Inventory when it is deployed. Each
stable version is published on NPM as @eotl/ui-inventory
package.
Important:
This setup assumes the presence of open-inventory in a parallel directory (both ui-inventory
, and open-inventory
must be in the same directory.)
This is needed to be able to update the UI files in the open-inventory/public
, each time there is a change in ui-inventory
.
Our recommended method of developing ui-inventory
is using Docker. There are helper
commands in the Makefile
to run various Docker operations.
The first time setting up your environment run:
$ make first-run
Next time, just start Docker and run the dev server with:
$ make dev
To upgrade or install new NPM packages:
$ make up
$ make packages
To do anything else in the user or root shell such as install OS depedencies:
$ make shell
$ make shell-root
open-inventory
To see your changes live in the running instance of open-inventory
, make sure that make dev
is running within ui-inventory
.
How is that working under the hood? open-inventory/public
is mounted as volume within ui-inventory/docker-compose.yml
.
If you prefer to not use Docker you can run things manually. You need a locally
installed Node JS environment and yarn
package manager.
Install the packages:
$ yarn
Run local server:
$ yarn serve
Build files for production use or new package
$ yarn build
The compiled app files will be in the ./open-inventory-public/
directory. Please make sure the directory has appropriate permissions.
FAQs
UI Inventory ============
The npm package @eotl/ui-inventory receives a total of 4 weekly downloads. As such, @eotl/ui-inventory popularity was classified as not popular.
We found that @eotl/ui-inventory demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.