
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@jupiterone/graph-bamboohr
Advanced tools
You must have Node.JS installed to run this project. If you don't already have it installed, you can can download the installer here. You can alternatively install Node.JS using a version manager like fnm or nvm.
First, you'll need to
install yarn. Then, from the
root of this project, run yarn install to install dependencies.
An integration executes against a configuration that provides credentials and
any other information necessary to ingest data from the provider. The
configuration fields are defined in src/instanceConfigFields.ts while the
configuration values are stored in a .env file at the root of this project.
This allows the integration to automatically load the field values and complain
when they're not provided.
Create a .env file at the root of this project and add environment variables
to match what is in src/instanceConfigFields.ts. The .env file is ignored by
git, so you won't have to worry about accidentally pushing credentials.
Given this example configuration:
import { IntegrationInstanceConfigFieldMap } from '@jupiterone/integration-sdk-core';
const instanceConfigFields: IntegrationInstanceConfigFieldMap = {
clientId: {
type: 'string',
},
clientSecret: {
type: 'string',
mask: true,
},
};
export default instanceConfigFields;
You would provide a .env file like this:
CLIENT_ID="client-id"
CLIENT_SECRET="supersecret"
The snake cased environment variables will automatically be converted and
applied to the camel cased configuration field. So for example, CLIENT_ID will
apply to the clientId config field, CLIENT_SECRET will apply to
clientSecret, and MY_SUPER_SECRET_CONFIGURATION_VALUE will apply to a
mySuperSecretConfigurationValue configuration field.
To start collecting data, run yarn start from the root of the project. This
will load in your configuration from src/index.ts.
Please reference the JupiterOne integration development documentation for more information on how to use the SDK.
See docs/development.md for details about how to get started with developing this integration.
More information about the resources covered by this integration and how to setup the integration in JupiterOne can be found in docs/jupiterone.md.
The history of this integration's development can be viewed at CHANGELOG.md.
FAQs
A Graph Conversion Project for BambooHR
The npm package @jupiterone/graph-bamboohr receives a total of 2 weekly downloads. As such, @jupiterone/graph-bamboohr popularity was classified as not popular.
We found that @jupiterone/graph-bamboohr demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.