
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
ci-cd-apier
Advanced tools
APIer is a library that allows you to launch its backend code with Flask-like syntax using GitLab CI/CD. All the requests and responses are processed with e2e encryption using age, so nobody has access to the data except the sender (web page) and the receiver (GitLab job in memory).
To see the full example, take a look at the example repository.
Whenever the client calls a backend via APIer script, e.g.:
const APIer = new APIer(
'$AGE_PUBLIC_KEY$',
'$GITLAB_PIPELINE_ENDPOINT$',
'$GITLAB_TOKEN$'
);
const totalSum = await APIer.sendRequest('sumNumbers', [1, 2, 3, 4, 5]);
A pipeline is triggered. Example code that handles the request in the pipeline may be:
app = APIER(environ["AGE_SECRET_KEY"])
@app.route("echo")
def endpoint_echo(data: any) -> str:
return f"You said: {data}. Enjoy :)"
@app.route("sumNumbers")
def endpoint_sum(data: list[int]) -> str:
return str(sum(data))
app.process_requests()
There also exists Python client for APIer in ci_cd_apier.client
package.
FAQs
ci-cd-APIer -- Flask-like API framework for GitLab CI/CD pipelines
We found that ci-cd-apier demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.