
Research
/Security News
Popular Tinycolor npm Package Compromised in Supply Chain Attack Affecting 40+ Packages
Malicious update to @ctrl/tinycolor on npm is part of a supply-chain attack hitting 40+ packages across maintainers
icastdownloader
Advanced tools
The iCast audiobooks service is really good but I can't use it because of the need for constant network connection, additinally the phone app UX is not optimal and has some bugs (Jumping between chapters, Stop playing for no reason, Not remembering last stop). So i developed this tool so i could listen in my favourite audiobooks player.
To use this you should have an active subscription to iCast service.
The simplest way of using this is with npx
, just run:
npx icastdownloader
and follow the instructions.
if you want to run it without npx
just follow these command:
git clone https://github.com/20lives/iCastDownloader.git
cd iCastDownloader
npm run start
# or yarn start
I am not responsible for any use of this program, please read iCast terms of use before using this.
FAQs
Download iCast hebrew audiobooks
We found that icastdownloader demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Malicious update to @ctrl/tinycolor on npm is part of a supply-chain attack hitting 40+ packages across maintainers
Security News
pnpm's new minimumReleaseAge setting delays package updates to prevent supply chain attacks, with other tools like Taze and NCU following suit.
Security News
The Rust Security Response WG is warning of phishing emails from rustfoundation.dev targeting crates.io users.