
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
ids-identity
Advanced tools
[!IMPORTANT] This repo has been moved to https://oxford.awsdev.infor.com/infor-design/design-system
The Infor Design System is a set of use-case driven design practices, development tools, and support documentation to create a cohesive user experience across all Infor CloudSuite applications.
This repository contains the fundamentals of the Infor Design System, including design tokens, which are design metadata, and basic tools like icons. For more information, see design.infor.com.
To get started, :arrow_down:download the latest release :arrow_down: of our IDS Design Kit. In that package, you'll find icons, font files for Source Sans Pro, and our design tokens.
See our getting started page for more information.
Part of the Infor Design System is a package of different assets that create the Infor identity. This includes the design tokens, font files, and icons.
Install this into your project with:
npm install --save-dev ids-identity
Then look in node_modules/ids-identity
for the assets.
For designers and developers wanting to build these assets locally, see our developer guide.
--dry-run=false --no-increment --no-npm
. Before doing this, remove the tag/version from github so it gets re-created.Create a .env file and populate it. AWS keys are required only for local docker runs.
AWS_ACCESS_KEY_ID=
AWS_SECRET_ACCESS_KEY=
NPM_TOKEN=""
GITHUB_ACCESS_TOKEN=
DOCS_API_KEY=
# specify the semantic version target X.X.X
RELEASE_INCREMENT=minor
RELEASEIT_FLAGS="--dry-run=true"
Then make build
.
For questions and support, please open an new Issue.
FAQs
Infor Design System Design Assets
The npm package ids-identity receives a total of 2,040 weekly downloads. As such, ids-identity popularity was classified as popular.
We found that ids-identity demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.