Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
A command line utility that generates the Node.js LTS schedule as a graph. Accepts JSON LTS data and a date range as inputs. Writes the LTS graph as HTML, SVG, and PNG files.
node bin/lts.js -s 2017-04-01 -e 2019-04-01 -h output.html -g output.svg -p output.png
-d
, --data
- The path of the input JSON file. The JSON file should be of the same format as the one in Node's Release repo. If this option is not provided, lts
uses its own bundled JSON file.-s
, --start
- The start date of the graph. Internally, this option is passed to new Date()
. Optional. Defaults to the current date.-e
, --end
- The end date of the graph. Internally, this option is passed to new Date()
. Optional. Defaults to one year from the current date.-h
, --html
- The location to write the HTML output file. Optional.-g
, --svg
- The location to write the SVG output file. Optional.-p
, --png
- The location to write the PNG output file. Uses svg2png
under the hood. Optional.-a
, --animate
- Animate the bars of the graph on load.-m
, --excludeMain
- Exclude the Main (unstable)
bar that is ever-present at the top of the graph. Optional. Defaults to false-n
, --projectName
- Provide a project name for the graph which will be displayed on the left axis beside each version. Optional. Defaults to Node.js
FAQs
Generate the Node.js LTS schedule
We found that lts demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.