Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
google-cloud-secrets-manager
Advanced tools
This Node.js project demonstrates how to create and retrieve secrets from Google Cloud Secrets Manager.
Before you begin, make sure you have the following:
Install project dependencies:
npm install google-cloud-secrets-manager
To use the different functions in this project, you need to set up the following environment variables:
GCP_USER: Your Google Cloud Platform user (email) associated with the project. GCP_KEY: The path to your GCP service account key file (JSON file). GCP_PROJECT_NAME: The name of your GCP project where Secrets Manager will be used.
You can set these variables by creating a .env file in the root of the project:
GCP_USER=your-user@example.com
GCP_KEY=/path/to/your/key.json
GCP_PROJECT_NAME=your-project-name
Make sure to replace the values with your actual GCP information.
The project provides the following functionalities:
Creating a new secret in Google Cloud Secrets Manager. Retrieving the value of a secret. To run the code demonstrating these functionalities, use the following commands:
Create a secret:
const secretsStore = new SecretsStore();
await secretsStore.storeCredential('secretId', 'secret', {'label1':'labelValue1', 'label2':'labelValue2'});
Get the value of a secret:
const secretsStore = new SecretsStore();
await secretsStore.retrieveCredential('secretId');
Update the value of a secret:
const secretsStore = new SecretsStore();
await secretsStore.updateCredential('secretId', 'newSecret');
FAQs
Google Cloud Secrets Manager Operator
The npm package google-cloud-secrets-manager receives a total of 0 weekly downloads. As such, google-cloud-secrets-manager popularity was classified as not popular.
We found that google-cloud-secrets-manager demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.