
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
serviser-cli
Advanced tools
Implements serviser http & REPL App which spies on AppManager's apps to provide
integrity status of the running service.
var Service = require('serviser').Service;
//your service definition
module.exports = new Service;
//hookup the plugin to the serviser
require('serviser-cli');
Require the plugin module preferably at the bottom of your index.js file of your project (aka. where your Service definition should be)
Add the cli app
{
listen: {
cli: {
port: '3000'
}
},
apps: {
//It expects the app to be under "apps.cli" name
cli: {
baseUrl: {$join: [
'http://127.0.0.1:',
{$ref: '#listen/cli/port'}
]},
listen: {$ref: '#listen/cli/port'},
show: false //if true - attaches REPL node console to the service process
}
}
}
TIP: When you want to quickly show the REPL console and editing of the config file is not desirable, you can override the config option inline like so:
node bin/www apps.cli.show 1
After you are connected to the console. The help command is your friend.
Use it to get an overview of available commands and their usage
GET /api/v1.0/integrity - responds with 409 status in case of integrity error or 200 signalizing all OK.
FAQs
CLI plugin module for serviser
We found that serviser-cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.