
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
svn-resolver
Advanced tools
SVN pluggable resolver for Bower, overriding and enhancing the default functionality
SVN pluggable resolver for Bower. Bower has some support for SVN, but this resolver overrides the default to provide enhanced functionality to better support typical SVN workflows. So far it allows storage of credentials in .bowerrc
, provides the capability to update from trunk, and allows SVN targets which do not use the typically trunk/tags structure.
Either install globally with npm:
npm install --global svn-resolver
or add as a local dependency in your package.json.
Add the following to .bowerrc
:
{
"resolvers": [
"svn-resolver"
],
"svnResolver": {
"username": "[USERNAME]",
"password": "[PASSWORD]"
}
}
Credentials are optional, if not provided it will use the credentials saved by SVN (if any). There are clearly security considerations with storing credentials in plain text within .bowerrc
, but it may be helpful to simplify a build process.
Now in bower.json we can use dependencies of the form:
"dependencies": {
"MyPrivateDependency": "svn+https://svn.example.com/my-private-dependency#",
}
Typically the target directory in SVN will need to use the conventional trunk/branches/tags directory structure. Versions are mapped as follows:
#
for the latest revision from trunk (bower update
works)#trunk
for the trunk, but bower update
will not pull down new revisions. This probably has little use but is provided to match the default Bower behaviour.#[tag]
for tags/[tag]
(bower update
will not work but since tags should not change, this should not be an issue)#[revision].0.0
or #r[revision]
will use trunk at the specified [revision]
.Alternatively, it is possible to use a target directory that does not use the trunk/branches/tags structure by appending -no-trunk
to the version:
#-no-trunk
for the latest revision#r[revision]-no-trunk
for a specific revisionFAQs
SVN pluggable resolver for Bower, overriding and enhancing the default functionality
The npm package svn-resolver receives a total of 0 weekly downloads. As such, svn-resolver popularity was classified as not popular.
We found that svn-resolver demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.