
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
@looker/api-explorer
Advanced tools
Use this OpenAPI Explorer to read any OpenAPI specification and explore its methods and types. Fast and powerful searching is also supported.
This is an Open Source project that builds on the specification processing created in the Looker SDK Codegen project.
This package uses Yarn. See the Yarn installation instructions if you need to install it.
To install dependencies, run:
yarn install
followed by:
NOTE: For API-explorer to build all other packages must have been built at least once. Use yarn build to do a complete build.
yarn workspace @looker/api-explorer develop
will start the development server and monitor for changes.
To see the other scripts supported by the package, do
yarn workspace @looker/api-explorer run
The API Explorer includes end-to-end tests using Puppeteer.
This command will automatically start the development server (yarn develop) and run the tests against it.
yarn workspace @looker/api-explorer run test:e2e
To run the E2E tests against a remote Looker instance, you must provide your API client credentials.
This runs the local development server (with your code changes) but proxies API requests to the remote Looker instance.
API_PROXY_TARGET=https://<your-looker-instance> \
LOOKER_CLIENT_ID=<your-client-id> \
LOOKER_CLIENT_SECRET=<your-client-secret> \
yarn workspace @looker/api-explorer run test:e2e
FAQs
Looker API Explorer
The npm package @looker/api-explorer receives a total of 23 weekly downloads. As such, @looker/api-explorer popularity was classified as not popular.
We found that @looker/api-explorer demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 9 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.