Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Client for Gordo project.
Documentation is available on Read the Docs
At least python 3.9 need to be installed in the system first.
In order to install or uninstall this library run following commands.
# Install
pip install gordo-client
# Uninstall
pip uninstall gordo-client
Install poetry.
Setup and run development shell instance:
> poetry install
> poetry shell
You could also install and apply pre-commit hooks.
Run poetry install
to install or re-install all dependencies.
Run poetry update
to update the locked dependencies to the most recent
version, honoring the constrains put inside pyproject.toml
.
You could also install and apply pre-commit hooks.
Install docker (or similar container manager) if you want to run test-suite.
Run tests (except docker-related ones):
> poetry run pytest -n auto -m "not dockertest"
Run docker-related tests:
> poetry run pytest -m "dockertest"
We welcome contributions to this project! To get started, please follow these steps:
git clone https://github.com/your-account/your-project.git
git checkout -b your-feature-or-bugfix-branch
git commit -m "Add a new feature" -a
git push origin your-feature-or-bugfix-branch
We'll review your changes and work with you to get them merged into the main branch of the project.
FAQs
Gordo client
We found that gordo-client demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.