
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
aurora
Advanced tools
.. image:: docs/figures/aurora_logo.png :width: 900 :alt: AURORA
|
.. image:: https://img.shields.io/pypi/v/aurora.svg :target: https://pypi.python.org/pypi/aurora
.. image:: https://img.shields.io/conda/v/conda-forge/aurora.svg :target: https://anaconda.org/conda-forge/aurora
.. image:: https://img.shields.io/pypi/l/aurora.svg :target: https://pypi.python.org/pypi/aurora
Aurora is an open-source package that robustly estimates single station and remote reference electromagnetic transfer functions (TFs) from magnetotelluric (MT) time series. Aurora is part of an open-source processing workflow that leverages the self-describing data container MTH5 <https://github.com/kujaku11/mth5>, which in turn leverages the general mt-metadata <https://github.com/kujaku11/mth5> framework to manage metadata. These pre-existing packages simplify the processing by providing managed data structures, transfer functions to be generated with only a few lines of code. The processing depends on two inputs -- a table defining the data to use for TF estimation, and a JSON file specifying the processing parameters, both of which are generated automatically, and can be modified if desired. Output TFs are returned as mt-metadata objects, and can be exported to a variety of common formats for plotting, modeling and inversion.
Documentation for the Aurora project can be found at http://simpeg.xyz/aurora/
Suggest using PyPi as the default repository to install from
pip install aurora
Can use Conda but that is not updated as often
conda -c conda-forge install aurora
MTH5 Documentation and Examples <https://mth5.readthedocs.io/en/latest/index.html>_.RunSummary.KernelDataset.Config.process_mth5 and out put as a mt_metadata.transfer_function.core.TF object which can output [ EMTFXML | EDI | ZMM | ZSS | ZRR ] files.FAQs
Processing Codes for Magnetotelluric Data
We found that aurora demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.