
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@pkgjs/statusboard
Advanced tools
A WIP attempt to centralize all the work being done in a community
of GitHub projects. When you have work spread across multiple repos
and multiple orginizations, it is often hard to track things. This
is what @pkgjs/statusboard
aims to solve.
This repository is managed by the Package Maintenance Working Group, see Governance.
https://expressjs.github.io/statusboard/
create
command to setup a new projectWARNING: work in process, the following doesn't work yet, but soon!
The easiest way to create a status board for your project is using Github Pages. To get started, create a new repo for your project and clone it to your development machine. In the new directory run the following:
# Creates a statusboard project
# @TODO make this command actually work as it does not right now
$ npx @pkgjs/statusboard create
# Setup your config in `index.js
# Then commit your work
$ git commit -am "statusboard setup"
# Create an orphan branch for our builds
$ git checkout --orphan gh-pages
# Remove the files we dont need here
$ git rm -rf .
# Create a .nojekyll file, this turns off pesky github pages stuff
$ touch .nojekyll
$ git commit --am "github pages initial commit"
# Now we setup the branch as a working tree on the master branch
$ git checkout master
$ mkdir build
$ git worktree add build gh-pages
# Now we can run the index and build
$ npm run build
# Now we should have a site in ./build, we can
# commit and push the branches now
$ cd build && git add . && git commit -m "our new statuspage" && git push
FAQs
A dashboard for project status
The npm package @pkgjs/statusboard receives a total of 21 weekly downloads. As such, @pkgjs/statusboard popularity was classified as not popular.
We found that @pkgjs/statusboard demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 11 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.