
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
cli to interface with kintohub api
Usage: kinto [options] [command]
Options:
-v, --version output the version number
-h, --help output usage information
Commands:
init [options] Initialize the base env
view-config view the config
clear-config remove all the saved config (need to do `kinto init` after)
proxy [options] [appname] proxy for kintoblocks inside the provided kintoapp
apidocs [options] validates/parse apidocs
kinto apidoc
Supports the following
-l
for linting (no output file)
-e <path>
for ignoring (can have multiple)
The tool only spits out
kinto-apidoc.json
not a whole folder
Processing
Modify groups for @apiSuccess
and @apiError
to modify 200
, 400
to Success_200
and Error_400
, so it allows the user to use groups like @apiSuccess (200)
in the code
Default Groups
add the following custom groups if non is specified
@apiParam
adds Body
as the default group@apiHeader
adds Header
as the default group@apiSuccess
adds 200
as the default group@apiFailer
adds 400
as the default groupValidations
@apiName
Validates the following:
@api
required http verb and url per endpoint@apiName
check uniqueness per project and required for each endpoint@apiSuccess
Success_<number>
) or Session
@apiError
Error_<number>
) or Session
@apiHeader
Header
,Session
or Config
@apiParam
Url
,Body
or QueryString
When validation fails, no file is gonna be outputted and the process will exit with error
use example.localdebug.config.json
as a local debug example config
to run kinto proxy with a config:
kinto proxy -f app.config.json
@apiName
if non is provided apidoc generates oneFAQs
KintoHub CLI Tools
The npm package kinto-cli receives a total of 23 weekly downloads. As such, kinto-cli popularity was classified as not popular.
We found that kinto-cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.