Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
howsmydriving-nyc
Advanced tools
@HowsMyDrivingWA supports plug-in npm modules to add additional cities/regions.
This project is a template that you can copy and add your code to in order to implement your favorite region.
Requirements:
export class NYCRegion extends Region {
constructor(name: string) {
super(name);
}
GetCitationsByPlate(plate: string, state: string): Promise<Array<Citation>> {
return new Promise<Array<Citation>>((resolve, reject) => {
// Your code to get the citations and return as an array.
//
// The objects you return must implement ICitation but can have
// any number of additional properties.
// Note: AWS DynamoDB is currently used as the store which means that
// none of the properties of your returned objects can be undefined
// or empty strings because the world's richest man seems to think
// that makes sense.
});
}
ProcessCitationsForRequest(
citations: ICitation[],
query_count: number
): Array<string>
let tweets: Array<string> = [];
// Your code to create the list of tweets you want posted.
// It is OK for any or all of the strings to be > 280 chars
// in length. They will be split into multiple tweets on a line
// break if one exists (if not, it will be split at 280 chars).
// Return the strings in the order they should be tweeted.
return tweets;
}
}
Adding a new region module to HowsMyDriving .env file (you'll need @GlenBikes to invite you to the project as a collaborator):
The string you give for the region is the npm module name (i.e. what you'd specify in an import statement to import your project).
{
REGIONS="howsmydriving-seattle, howsmydriving-dummy, your-new-region"
}
How to contribute: CONTRIBUTING.md.
Find this useful? Buy @GlenBikes a coffee
Powered by Glitch
\ ゜o゜)ノ
FAQs
NYC region plug-in for @HowsMyDrivingWA.
The npm package howsmydriving-nyc receives a total of 8 weekly downloads. As such, howsmydriving-nyc popularity was classified as not popular.
We found that howsmydriving-nyc demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.