Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
@renovosolutions/cdk-library-certbot
Advanced tools
AWS CDK Construct Library to manage Lets Encrypt certificate renewals with Certbot
A CDK Construct Library to automate the creation and renewal of Let's Encrypt certificates.
This library creates a Lambda function that utilizes Certbot to create certificates. Upon completion those certs are imported to AWS Certificate Manager (ACM) and uploaded to S3 and the email used for the certs is sent a notification. The function is also assigned an every Monday trigger to check if there is under 30 days remaining on the certificates that have been imported to ACM and if so it re-issues new certificates.
This construct will create all required components but optionally allows the users to pass their own S3 bucket, SNS topic, enable Lambda insights, and other customization as needed.
FAQs
AWS CDK Construct Library to manage Lets Encrypt certificate renewals with Certbot
The npm package @renovosolutions/cdk-library-certbot receives a total of 0 weekly downloads. As such, @renovosolutions/cdk-library-certbot popularity was classified as not popular.
We found that @renovosolutions/cdk-library-certbot demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.