
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
To install the command line tool run an npm install
npm install -g @red5/cli
Once installed you can create projects and project files.
New projects are created by going to the directory that you want to create a new project within. The command will then create a new directory and install everything into that directory.
red5 new <project-name>
The following steps are taken:
git clone the bare bones project from githubhttp://localhost:5000 within a browser to make sure everything worksThis allows for seeing all of the commands that are usable at the current path. This includes builtin commands and commands that are listed in a projects app/commands directory.
red5 list
Adds a supported @red5 package to the current project.
red5 add <package-name>
The following steps are taken:
@red5/<package-name>)npm i -s @red5/<package-name>Removes a supported @red5 package from the current project.
red5 remove <package-name>
The following steps are taken:
@red5/<package-name>)npm rm -s @red5/<package-name>Displays a list of packages that can be installed via package:add.
red5 package:list
Make controller can create 3 different types of controllers:
Creates a basic controller containing only a main endpoint. This is the default action.
red5 make:controller <controller-name>
Creates an API controller containing only API endpoints
red5 make:controller <controller-name> --api
Creates a Resource controller containing all resource endpoints
red5 make:controller <controller-name> --resource
Make Middleware will make middleware that can then be hooked into within your routes.
red5 make:middleware <middleware-name>
Starts an instance of a red5 server application. This command will not hang the terminal and will start the server in the background. A pid will be written to the red5.json file in order to stop the service upon server:stop.
The server will watch for file changes in: app, config and routes. When a file changes the server will restart with the new changes.
Note: Calling server:start repeatedly on the same project will shutdown the current running server if one started successfully and start a new one thus removing the need for a server:restart command.
Note: If the server fails to start a new attempt will be taken to start the server. If the restart fails five times a restart attempt will not be taken a sixth time.
# Starts the server in the current directory
red5 server:start
# Start the server in the specified directory
red5 server:start /path/to/server/root
Stops an instance of a red5 server application. When the server is stopped, the pid will be removed from the red5.json file.
# Stops the server in the current directory
red5 server:stop
# Stops the server in the specified directory
red5 server:stop /path/to/server/root
Displays the tail of the server log file at storage/framework/logs/server.log. This file will be created upon server:start, and truncated upon server:stop.
Note: Logging will not be logged to this file when in production mode.
# Shows the server log in the current directory
red5 server:log
# Shows the server log in the specified directory
red5 server:log /path/to/server/root
Displays all the servers that are currently running.
red5 server:list
FAQs
red5 command line tools for managing and creating red5 projects.
We found that @red5/cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.