
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
@vltpkg/keychain
Advanced tools
The filesystem keychain for @vltpkg/registry-client
This is a tool to store and retrieve private keys for use in the
@vltpkg/registry-client.
import { Keychain } from '@vltpkg/keychain'
// define a keychain with a given application scope
const kc = new Keychain('vlt/auth')
// fetch the auth for a given origin, for example.
// will load file on demand when first get() called.
const auth = await kc.get('https://registry.npmjs.org')
// set a value like this
kc.set('https://some-registry.com', 'Bearer newtoken')
// will attempt to save on process end if there are pending
// writes, but only if the file has not been modified since.
// you can also trigger a write explicitly.
await kc.save()
FAQs
The filesystem keychain for `@vltpkg/registry-client`
The npm package @vltpkg/keychain receives a total of 18,461 weekly downloads. As such, @vltpkg/keychain popularity was classified as popular.
We found that @vltpkg/keychain demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.