Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@proso-io/fobu
Advanced tools
A robust form builder and renderer with a customizable API and a beautiful out-of-the-box experience.
Fobu is a lightweight form builder built with extensive customization, straight-forward API and beautiful out-of-the-box experience in mind. Its built using React.
Demo URL - https://codesandbox.io/s/awesome-platform-s01vj?fontsize=14&hidenavigation=1&theme=dark&view=preview
Who are we? Just a bunch of guys who genuinely like to build software and think that doing live projects is the best way to learn. No dummy calculator projects, or static sites that do nothing. Real, useful software.
We have been working with the non-profit Goonj, with software they need to be more effective in their operations (for free, we don't charge non-profits for this). Goonj uses the under-utilized and excess urban household material as a tool for rural development across 23 states in India. They need a way of centrally managing all their activities and its associated data. Fobu started as a subcomponent within that project.
Fobu needs to be proficient at the following -
Fobu is very young but has big plans. If you want to be an early contributor, now is a good time. We are literally just getting started. Unlike other projects, we want to help new developers get into this. Make mistakes, write shitty code so that we can tell you how to get better.
We will be using GitHub issues to create tasks for this project. Feel free to comment on the issue that you see unassigned at the moment with your intention to take up. Here's the process once you have picked a issue -
If any of this doesn't make sense to you, raise an issue with the question tag / tweet
FAQs
A robust form builder and renderer with a customizable API and a beautiful out-of-the-box experience.
We found that @proso-io/fobu demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.