
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
Provisions local interdependent node modules referenced as file dependencies so you don't have to do this manually for each one. Removes the need for packages to be published to npm or a local npm repo. Useful when you want to develop modular applications which rely on shared or common infrastructure local modules without having them deployed on npm.
The module is released in the public npm registry and can be installed by running:
npm install --save inframod
Module registration requires the definition of the following section within package.json containing the module registration array
"modules": [
{
"path": "/foo",
"provisionCommand": "yarn install && yarn run build"
},
{
"path": "/bar/bar",
"provisionCommand": "yarn install && yarn run build"
}
]
The required fields for a module definition are
The provision-modules command builds a lightweight dependency graph and synchronously iterates it and provisions each module so that it's ready to be referenced by any consumer.
provision-modules --key-path modules
For details about this command run
provision-modules -h
The example folder contains a use case which involves the creation of a base docker image containing the infrastructure modules referenced by a modular app.
FAQs
Local node modules registration and provisioning micro-framework
We found that inframod demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.