
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@yannickoo/esti
Advanced tools
Esti is a tool which helps you organizing voting rounds. You can create a room for your voting and invite other users to it. After they have joined you can ask a question which can be answered by predefined options. You find the average answer and select the winner. That's it. In my case I'm using Esti for scrum projects which need an estimated backlog and Esti helps us.
It's annoying when doing backlog estimation meetings remotely and you need to write all points on pieces of paper. Then you need to show your estimation in the webcam so your project manager can see that. Welcome to the year 2016 :tada: Let's do something useful with our time and simply join a room where all developers can simply vote without getting influenced by others :hatching_chick:
You can start by creating a new room on esti.io. Check the wiki for a step by step tutorial.
# Clone repository
$ git clone https://github.com/yannickoo/esti.git
# Go into repository
$ cd esti
$ npm install && npm start
Open http://localhost:4200 in your browser.
Pull requests and stars are always welcome. For bugs and feature requests, please create an issue.
FAQs
:one: :two: :three: :five: :eight: :one::three:
The npm package @yannickoo/esti receives a total of 0 weekly downloads. As such, @yannickoo/esti popularity was classified as not popular.
We found that @yannickoo/esti demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.