
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@opentelemetry/resource-detector-container
Advanced tools
Opentelemetry resource detector to get container resource attributes
component owners: @abhee11
Resource detector for container id.
Compatible with OpenTelemetry JS SDK 2.0+.
npm install --save @opentelemetry/resource-detector-container
import { detectResources } from '@opentelemetry/resources';
import { containerDetector } from '@opentelemetry/resource-detector-container'
const resource = await detectResources({
detectors: [containerDetector],
})
const tracerProvider = new NodeTracerProvider({ resource });
This package uses @opentelemetry/semantic-conventions version 1.22+, which implements Semantic Convention Version 1.7.0
Populates container.id for processes running on containers supporting : docker( cgroup v1 or v2 ) or with containerd
| Resource Attribute | Description |
|---|---|
container.id | Value parsed from file /proc/self/cgroup (cgroup v1). If it doesn't exist, parse the value from file /proc/self/mountinfo (cgroup v2) |
Apache 2.0 - See LICENSE for more information.
FAQs
Opentelemetry resource detector to get container resource attributes
The npm package @opentelemetry/resource-detector-container receives a total of 4,463,917 weekly downloads. As such, @opentelemetry/resource-detector-container popularity was classified as popular.
We found that @opentelemetry/resource-detector-container demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.