
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
In the world of microservices to test locally our application, we often need to start multiple processes, each with its own options and environment. Using fireup we can do this with a single command and watch the output in a single console, just like a monolith application.
Inspired by Foreman, node-foreman and Cloud Foundry manifest.yml.
What's in:
What's out:
$ [sudo] npm install -g fireup
fireup.yml
processes:
proxy:
cmd: node proxy.js
env:
PORT: 8080
FORWARD: >
{
"target": "http://localhost:8181",
"tomeout": 15000
}
app:
cmd: node start.js
env:
PORT: 8181
$ fireup
fireup [<fireup.yml>]
Start the processes defined in the given yaml file.
By default loads fireup.yml
from current directory.
An object inside which each property describes a processes to start. The property name is the process name. The value can be a shell command to start the respective process. Alternatively it can be an object specifying additional process properties.
processes:
app: node start.js
Shell command to start the process Mandatory
Additional environment variables for this process.
Parent environment is inherited by the process.
Can be used also at root level of fireup.yml
to define common environment variables for all processes.
Process current working directory.
By default the directory of fireup.yml
(base directory).
If dir
is relative, it is resolved from the base directory.
See release history in GitHub. There are breaking changes since version 1.
FAQs
Simple process launcher for local development
The npm package fireup receives a total of 0 weekly downloads. As such, fireup popularity was classified as not popular.
We found that fireup demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.