
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
Sora (そら) 是一个基于Web的文件 / 资源管理系统. 基于node.js + mongodb.
Sora 项目目前还处于很初步的原型阶段. 这个项目的初衷和开发目标是用来管理硬盘里大量 ACG 方面的资源, 如动画 BDRip, 同人志压缩包, 无损音乐, 轻小说等; 通过自动 TAG 系统提供方便的筛选和查找文件功能; 并且具有 Wiki 功能, 可以存储作品相关信息和资料; 提供分享和公开发布功能.
git clone https://github.com/sagan/sora.git && cd soranpm installcp config-sample.js config.js && vim config.js. 默认的配置文件是js文件,
可以在其中执行任意代码. 你也可以使用json格式的配置文件(命名为config.json即可)node app.jsFAQs
Sora ===
We found that sora demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.