data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
A small python based CLI utility to monitor BigBlueButton-Usage.
The easiest way to install bbbmon is to install it from the Python Package Index (PyPi). This project uses python poetry for dependency management, so you could also run it without installing the package system wide, see instructions below.
sudo pip3 install bbbmon --upgrade
Then run with:
bbbmon
Clone the repo:
git clone https://code.hfbk.net/bbb/bbbmon.git
Make sure you have poetry installed. Install instruction for poetry can be found here. From inside the project directory run:
poetry install
Run bbbmon with:
poetry run bbbmon
Run bbbmon config --new
to create a new default configuration file. bbbmon will always ask you before it creates or overwrites anything.
Within the config you can define one or more endpoints with running bbb instances – each with it's secret and bigbluebutton-URL. You can find the secret on your server in it's config-file via
cat /usr/share/bbb-web/WEB-INF/classes/bigbluebutton.properties | grep securitySalt=
A example configuration file could look like this:
[bbb.example.com]
securitySalt=MY_SUPER_SECRET_SECRET
bigbluebutton.web.serverURL=https://bbb.example.com/
[Föö]
securitySalt=MY_SUPER_SECRET_SECRET2
bigbluebutton.web.serverURL=https://bbb.foo.com/
The section names in the square brackets can be chosen arbitrarily (as long as they are unique) and will be used as display names (they support utf-8). It makes sense to keep them short as they can be used for filtering and/or ordering:
bbbmon meetings -e Föö
For help run:
bbbmon -h
bbbmon supports command abbreviations – these commands produce the same result:
bbbmon meetings
bbbmon meeting
bbbmon mee
bbbmon m
This works as long as there is no other command starting with the same letters.
FAQs
A small CLI utility to monitor bbb usage
We found that bbbmon demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.