Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
@sanbornagency/nodebb-theme-quest
Advanced tools
Follow nodebb.org's instructions for setting up an install of nodebb.
Select to use MongoDB for your database. You may restore the database after setup.
Should you choose to restore a database, you may download one in the NodeBB Admin.
This is not necessary if you're working with a clean data environment. However, if you've restored an API database with users, this step is highly recommended.
To retrieve a production database and restore it:
In NodeBB admin, select "PLUGINS" -> "SAAS" https://take.ms/6mt1hS
Select "DOWNLOAD BACKUP" https://take.ms/lfjH1
Use mongorestore
to restore the database locally
mongorestore -u <username> -p <password> -d <database> -c <collection>
ENSURE THAT IF YOU'VE CHOSEN A PRODUCTION DATABASE, PLEASE TURN OFF DIGESTS IN THE NODEBB ADMIN IMMEDIATELY FOLLOWING RESTORATION.
After installation is complete, install the following plugins with npm:
Installation is done in the nodebb directory with the commands:
npm install git+https://git@github.com/sanbornmedia/nodebb-plugin-write-api --save
npm install git+https://git@github.com/sanbornmedia/nodebb-plugin-friends --save
npm install git+https://git@github.com/sanbornmedia/nodebb-plugin-session-sharing --save
npm install git+https://git@github.com/sanbornmedia/nodebb-plugin-s3-uploads --save
Alternatively, add this to the nodebb's package.json:
"nodebb-plugin-friends": "git+https://git@github.com/sanbornmedia/nodebb-plugin-friends",
"nodebb-plugin-s3-uploads-updated": "git+https://git@github.com/sanbornmedia/nodebb-plugin-s3-uploads.git",
"nodebb-plugin-session-sharing": "git+https://git@github.com/sanbornmedia/nodebb-plugin-session-sharing.git",
"nodebb-plugin-write-api": "git+https://git@github.com/sanbornmedia/nodebb-plugin-write-api",
Install this theme with npm, i.e., Note: You must be logged into an npm account that is a member of the Sanborn Agency org.
npm install @sanbornagency/nodebb-theme-quest --save
Note: You must be logged into an npm account that is a member of the Sanborn Agency org.
Increment version number in package.json
and run npm publish
in project root.
Start redis using the command redis-server
to start, and redis-cli shutdown
to stop it.
In the nodebb directory, run ./nodebb build
to build assets, templates, etc. Then run ./nodebb dev
to start the server with logging.
Template file names and directory structure must mirror the templates they're replacing in the Node BB directory, as Node BB's build process will use the theme's templates to overwrite the defaults.
FAQs
Custom NodeBB theme for Quest Oracle Community
We found that @sanbornagency/nodebb-theme-quest demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.