Research
Security News
Malicious PyPI Package ‘pycord-self’ Targets Discord Developers with Token Theft and Backdoor Exploit
Socket researchers uncover the risks of a malicious Python package targeting Discord developers.
serverless-default-aws-resource-properties
Advanced tools
Set default properties a given CloudFormation resource should have based on type
This plugin allows you to set default properties a given CloudFormation resource should have based on type.
Install the plugin:
npm install -D serverless-default-aws-resource-properties
Register the plugin in serverless.yml
:
plugins:
- serverless-default-aws-resource-properties
Example:
custom:
defaultAwsProperties:
# Enable SSE and block public access for all S3 buckets
- Type: AWS::S3::Bucket
Properties:
BucketEncryption:
ServerSideEncryptionConfiguration:
- ServerSideEncryptionByDefault:
SSEAlgorithm: AES256
PublicAccessBlockConfiguration:
BlockPublicAcls: true
BlockPublicPolicy: true
IgnorePublicAcls: true
RestrictPublicBuckets: true
# Add logging configuration to all S3 buckets except resource with
# logical ID 'LoggingBucket'
- Type: AWS::S3::Bucket
Exclude:
- LoggingBucket
Properties:
LoggingConfiguration:
DestinationBucketName:
Ref: LoggingBucket
FAQs
Set default properties a given CloudFormation resource should have based on type
The npm package serverless-default-aws-resource-properties receives a total of 127 weekly downloads. As such, serverless-default-aws-resource-properties popularity was classified as not popular.
We found that serverless-default-aws-resource-properties demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover the risks of a malicious Python package targeting Discord developers.
Security News
The UK is proposing a bold ban on ransomware payments by public entities to disrupt cybercrime, protect critical services, and lead global cybersecurity efforts.
Security News
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.