
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
@notabene/ops
Advanced tools
Internal CLI tool to make development faster.
You'll need to install the following packages first:
Install the library globally using Yarn:
yarn global add @notabene/ops
or NPM:
npm i -g @notabene/ops
Make sure that the path to globally installed packages are in your $PATH
environment variable.
The Ops CLI is then available using nb
.
You can configure your AWS CLI by calling:
nb setup
Then you'll need to authenticate a session with AWS which you can initiate with:
nb login
List all databases in an environment:
nb db:list --env {env}
Get credentials for a specific database:
nb db:credentials --env {env} --db {db}
Connect to an AWS RDS database by mounting a local port:
nb db:connect --env {env} --db {db} --port {localPort}
Note: You can then use a tool like Postico to connect to the database on the local port you mounted.
Get a list of brokers for the Kafka instance running in an environment:
nb kafka:brokers --env {env}
Connect to the Kafka UI running in an environment by mounting a local port:
nb kafka:ui --env {env} --port {localPort}
Note: You can then access the UI by going to http://localhost:{localPort}
Get a list of all services running in an environment:
nb service:list --env {env}
Tail the logs of a service running in an environment:
nb service:logs --env {env} --service {service}
Get a list of Redis clusters running in an envionment:
nb redis:list --env {env}
Connect to a Redis cluster running in an environment by mounting a local port:
nb redis:connect --env {env} --cluster {cluster} --port {localPort}
Note: You can now use a tool like RedisInsight to connect to the Redis cluster on the port you mounted.
Get a list of static IPs of the NAT Gateways in an environment. This is usually useful for customers that need to whitelist the IPs of our services when we send webhooks to them.
nb network:ips --env {env}
Start a terminal session connected to the bastion instance running in an environment:
nb bastion:connect --env {env}
FAQs
CLI for Notabene Ops
The npm package @notabene/ops receives a total of 0 weekly downloads. As such, @notabene/ops popularity was classified as not popular.
We found that @notabene/ops demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.