Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@gliff-ai/etebase
Advanced tools
The Etebase TypeScript client API for the web, node and react-native!
Etebase is an end-to-end encrypted backend as a service. Think Firebase, but encrypted in a way that only your users can access their data.
Etebase makes it easy to build end-to-end encrypted applications by taking care of the encryption and its related challenges. It is fully open-source (clients and server) so anyone can review, audit or contribute to its development!
This repository is the JavaScript/TypeScript library for communication with an Etebase server (there also exists libraries for Python, Java, Kotlin, C/C++ and Rust). See https://docs.etebase.com/installation for details on how to install the library and dependencies.
The following is a minimal example of how to change the Etebase password.
import * as Etebase from 'etebase';
const etebase = await Etebase.Account.login("username", "password");
await etebase.changePassword("new password");
await etebase.logout();
There are more examples in the Guides section at https://docs.etebase.com/.
If you get build errors complaining about export = URI;
from urijs then
you need to set compilerOptions.allowSyntheticDefaultImports
to true in
tsconfig.json
.
git clone https://github.com/etesync/etebase-js
cd etebase-js
yarn install
yarn run build
Running tests requires a (test) Etebase server
running, defaulting to http://localhost:8033
, but can be overridden with the
environment variable ETEBASE_TEST_API_URL
.
cd ..
git clone https://github.com/etesync/server
cd server
... # Follow README.md install instructions
... # Build and start a server
cd ../etebase-js
env ETEBASE_TEST_API_URL=http://localhost:8033 yarn run test
Yarn is required for building this project, attempting to use npm will fail.
FAQs
Etebase TypeScript API for the web and node
The npm package @gliff-ai/etebase receives a total of 2 weekly downloads. As such, @gliff-ai/etebase popularity was classified as not popular.
We found that @gliff-ai/etebase demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.