Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
An open source full-stack generator built with React, Express, Node, and PostgreSQL.
t-rex-js
allows quick development of full-stack web applications using react
, express
, and sequelize
. It also uses socket.io
to support real-time dynamic interfaces.
npm install -g t-rex-js
Create a project and open the project:
t-rex create
cd <project_name>
Install server and client dependencies (from project root directory):
t-rex install
Provide a valid database url in config.json
:
"db_url" : <valid database url>
Start the application (from project root directory):
t-rex run
t-rex create
The create
command creates a t-rex
project in the current working directory. Project details will be prompted by the CLI.
t-rex install
Installs all required packages for both the server and a client. This command is a macro for the following:
npm install
cd client
npm install
This command is currently available only in the root directory of the project.
t-rex run
Runs the express server (backend) and the webpack development server for the react frontend. This command is a macro for the following:
yarn run start
cd client
yarn run start
This command is currently available only in the root directory of the project.
This file contains all of the editable system defaults supported by t-rex.
t-rex add
The add
command creates the ff:
/resources/<resource_name>
folder containing a dummy model for the resource/client/src/components
which displays all instances of the model associated with the resource/resources/index.js
NOTES:
db_url
in config.json
, running your application after adding a resource causes the Express server to crash.resource.js
and model.js
requires the user to insert model attributes (To be fixed)t-rex generate
The generate
command creates resources depending on the contents of generate.json
.
Format of generate.json:
// generate.json
{
"resources": {
"<resource_name>": {
"socket": <boolean>,
"methods": [<GET/POST/PUT/DELETE>],
"attributes": {
"<attribute>": "<sequelize_data_type>",
...
}
},
...
}
}
Name: Levy V. Medina II
Email: levymedina3@gmail.com
Mobile: (+63) 915 326 0223
FAQs
An open source full-stack generator built with React, Express, Node, and PostgreSQL.
The npm package t-rex-js receives a total of 65 weekly downloads. As such, t-rex-js popularity was classified as not popular.
We found that t-rex-js demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.