
Research
5 Malicious Chrome Extensions Enable Session Hijacking in Enterprise HR and ERP Systems
Five coordinated Chrome extensions enable session hijacking and block security controls across enterprise HR and ERP platforms.
changelog-manager
Advanced tools
This project is heavily inspired by GitLab's Changelog development guide.
In comparision to GitLab this project provides a standalone CLI which supports both steps:
You can customize these things:
Download from official website.
or use n version manager for Node.js via curl -L https://git.io/n-install | bash
npm install changelog-manager -g
You can also install it without -g but then you need to put the binary,
located in node_modules/.bin/changelog-manager to your $PATH.
The CLI provides 3 subcommands
addCreate an changelog entry (YAML file) in changelogs/unreleased
releaseAggregate files in changelogs/unreleased and transform them into a markdown file (CHANGELOGS.md)
strip-linkIf you have some links to your code (merge requests) in your CHANGELOG.md but your customers won't be able to open that (because your code is not open sources, etc.) you can remove those links wich this subcommand.
You can just invoke changelog-manager (or pass --help) to show help output.
For help output of a subcommand use -h instead!
Coming soon
Coming soon
FAQs
Interactive CLI to manage changelogs
The npm package changelog-manager receives a total of 0 weekly downloads. As such, changelog-manager popularity was classified as not popular.
We found that changelog-manager demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Five coordinated Chrome extensions enable session hijacking and block security controls across enterprise HR and ERP platforms.

Research
Node.js patched a crash bug where AsyncLocalStorage could cause stack overflows to bypass error handlers and terminate production servers.

Research
/Security News
A malicious Chrome extension steals newly created MEXC API keys, exfiltrates them to Telegram, and enables full account takeover with trading and withdrawal rights.