Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
imdone-echo-plugin
Advanced tools
Example plugin for iMDone that logs to the console
iMDone loads plugins that are mentioned in the .imdone/config.json
file in your project directory. It looks for them in your project directory under node_modules
then in your home directory under node_modules
, then by name. So if you include a plugin.js
that implements the plugin interface in your project, you can load it directly or install one using npm install -g
.
npm install -g imdone-echo-plugin
cd /my/project/folder
One that already has a .imdone/config
or create it.imdone -o
All plugins should expect a config and repo. Take a look at this example config. The plugins hash contains the plugin package name or path with it's config hash as the value. Repo is the Repository object for the project.
{
"exclude": [
"^(node_modules|bower_components|\\.imdone|target|build)\\/?|\\.(git|svn)|\\~$|\\.(jpg|png|gif|swp|ttf|otf)$"
],
"watcher": true,
"lists": [
{
"name": "TODO",
"hidden": false
},
{
"name": "DOING",
"hidden": false
},
{
"name": "DONE",
"hidden": false
}
],
"marked": {
"gfm": true,
"tables": true,
"breaks": false,
"pedantic": false,
"sanitize": true,
"smartLists": true,
"langPrefix": "language-"
},
"plugins": {
"imdone-echo-plugin": {
"name": "imdone:echo"
}
}
}
After starting iMDone and adding a project, you will find the .imdone/config.json
in the project directory.
FAQs
A sample iMDone plugin that logs to the console with debug
We found that imdone-echo-plugin demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.