
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
strapi-plugin-rtg-utils
Advanced tools
Some rooms to go common utilities to be used across all rtg strapi servers.
Some rooms to go common utilities to be used across all rtg strapi servers.
Installing through npm is currently not supported in strapi 3.x because this packaged is scoped under the @rtgdev npm org. So it best to install using github releases ex:
package.json
"strapi-plugin-rtg-utils": "git+git@github.com:RoomstoGoDigital/strapi-plugin-rtg-utils.git#v0.0.1",
For local development you should follow the strapi documentation guide for local plugin development. https://strapi.io/documentation/developer-docs/latest/development/local-plugins-customization.html
This plugin cannot run on its own. In order to develop locally you will need to install it into a local strapi insance. To accomplish this, you simply need to install the package using the file path. Ex:
npm i /Users/username/Documents/GitHub/strapi-plugin-rtg-utils
This will allow you to make changes to this repo and test them in a local strapi installation
This repo uses semantic releaes to push releases to github/npm. All releases are created on master branch. I will release will only be made if the commit messages match the default release patterns specified here:
https://github.com/semantic-release/commit-analyzer/blob/master/lib/default-release-rules.js
FAQs
Some rooms to go common utilities to be used across all rtg strapi servers.
We found that strapi-plugin-rtg-utils demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.