
Research
/Security News
Weaponizing Discord for Command and Control Across npm, PyPI, and RubyGems.org
Socket researchers uncover how threat actors weaponize Discord across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.
@fleetbase/verdaccio-fleetbase-auth
Advanced tools
Authentication to verdaccio for Fleetbase extension developers.
The Fleetbase Verdaccio Authentication Plugin provides robust authentication management for the Fleetbase registry, leveraging the Fleetbase API to authenticate users. This plugin is an essential component of the official Fleetbase registry (https://registry.fleetbase.io), which supports both npm and composer protocols and includes specific enhancements for the Fleetbase ecosystem.
To install the plugin, execute the following command in your terminal:
npm install @fleetbase/verdaccio-fleetbase-auth
Configure the plugin by adding the following settings to your Verdaccio server's config.yaml
file:
auth:
'@fleetbase/verdaccio-fleetbase-auth':
fleetbaseHost: https://api.fleetbase.io
fleetbaseApiKey: 1234567e
Ensure that the fleetbaseHost
and fleetbaseApiKey
are set to your Fleetbase API host and your specific API key respectively.
For additional security and flexibility, you can also configure the plugin using environment variables. Set the following variables in your environment:
FLEETBASE_HOST=https://api.fleetbase.io
FLEETBASE_API_KEY=your_fleetbase_api_key_here
These variables allow you to manage sensitive information outside of the repository, enhancing security.
After installation and configuration, the plugin will automatically handle authentication for the Fleetbase registry using the specified API credentials. This process is transparent to end users but requires valid credentials for access.
Contributions are welcome! If you have suggestions or improvements, please fork the repository and submit a pull request. For detailed instructions, refer to our CONTRIBUTING.md file.
This project is licensed under the AGPL v3 License. See the LICENSE.md file for more details.
If you encounter any issues or require assistance, please open an issue on our GitHub repository at https://github.com/fleetbase/verdaccio-fleetbase-auth/issues.
FAQs
Authentication to verdaccio for Fleetbase extension developers.
The npm package @fleetbase/verdaccio-fleetbase-auth receives a total of 5 weekly downloads. As such, @fleetbase/verdaccio-fleetbase-auth popularity was classified as not popular.
We found that @fleetbase/verdaccio-fleetbase-auth demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Socket researchers uncover how threat actors weaponize Discord across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.
Security News
Socket now integrates with Bun 1.3’s Security Scanner API to block risky packages at install time and enforce your organization’s policies in local dev and CI.
Research
The Socket Threat Research Team is tracking weekly intrusions into the npm registry that follow a repeatable adversarial playbook used by North Korean state-sponsored actors.