Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
configuration
Advanced tools
Performant and feature rich library for managing configurations/settings.
Performant and feature rich library for managing configurations/settings.
This library has been modeled after VSCode's settings system, and it can be used for implementing a similarly powerful settings system in your app.
global + local
setup can be implemented easily.foo.bar
) are supported for retrieving/setting/deleting entries.{ 'foo.bar': true, 'foo.baz': false }
) are supported transparently too.npm install --save configuration
For now you'll have to browse the test suite to check out exactly how to use this library.
//TODO: Write some actual usage instructions
MIT © Fabio Spampinato
FAQs
Performant and feature rich library for managing configurations/settings.
The npm package configuration receives a total of 335 weekly downloads. As such, configuration popularity was classified as not popular.
We found that configuration demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.