
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
@panter/catladder-build
Advanced tools
panter build & deploy tool for meteor apps
The most famous meteor deploy tool (meteor-up) uses docker and does not match our current setup.
So I decided to create a tool that integrates well in our setup and
reduces security issues with keys, app secrets, etc. by embracing pass
.
Also building cordova apps needs some scripts (in particular android).
Some commands also work on gitlab ci and can be used to deploy the app there. (look for the cat 🐱🔧CI )
Check the docu here.
npm install -g @panter/catladder-build
in the root of your project invoke
catladder init
this will ask you for some params and create a .catladder.yaml
-file which stores the configuration for the project.
You can (and should) safely add this file to git. Secrets will be stored in pass.
To create or update an environment (e.g. "staging"):
catladder setup <environment>
(e.g. catladder setup staging)
This will ask for additional properties and create a new file in pass
at "/customer/appname/environment/env.yaml"
which you can edit. This file can contain any secret that the server needs to know, e.g. amazon access keys, etc.
After saving catladder
creates a env.sh on the server under ~/app/env.sh
which contains
environment-variables for the server. (Warning: this file gets overwritten!)
You need to restart the server if you want to apply these changes
catladder restart <environment>
catladder deploy <environment>
this will create a bundle of the app (with meteor build
), upload it to the server and restart the server.
add platforms to meteor: meteor platform-add ios android
(in the meteor app directory)
For android you first need to invoke
catladder android-init <environment>
this will create a keystore-file which you can checkin to git. The corresponding password will be created in pass.
catladder build-apps <environment>
This will create and sign an android apk file and an xcode project, where you can upload the app to the app store.
FAQs
panter deploy tool for meteor apps
We found that @panter/catladder-build demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.