
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Grit is a simple git repo manager with limited remote object proxying, a http back-end and simple cli.
Grit is a simple and light-weight git repository manager or git-compatible digital asset management system with limited remote object proxying, a http back-end and easy to use command line, python and cli user interfaces.
.. note:: This is early prototype code, is missing many important features and probably won't work for you.
Documentation: http://rsgalloway.github.com/grit
1.1 Features
- Python WSGI "Smart HTTP" server
- Limited remote object proxying
- Stream blob data from remote repositories
- Hierarchical repos with top-down inheritance
- Check out individual blobs
- Python and HTTP+JSON read/write API
- Supports a centralized workflow
- Command line, Python and web UIs
- Git not required
1.2 Known Issues
Known issues as of this release:
1.3 Requirements
- Python (2.6.5)
- Dulwich (0.7.0)
- Git (optional)
1.4 Noted differences from git
::
$ easy_install grit
or, download the source and ::
$ sudo python setup.py install
2.1 Environment Variables
The following environment variables are used, but not required. ::
GRIT_LOG_LEVEL logging level (default is 20)
GRIT_SERVER_PORT default port to run the grit server on (default is 8080)
GRIT_STATIC_DIR filesystem location for serving web UI elements
3 Basic Usage
-------------
::
grit COMMAND [OPTIONS]
Commands:
new make new repo at url
co check out files from repo at url
ci check in files to repo at url
serve serve a repo or directory of repos
4 License
---------
See file named LICENSE for license terms governing over the entire project.
Some, explisitely labeled so constituent files/works are licensed under separate, more-permissive
terms. See disclaimers at the start of the files for details.
FAQs
Grit is a simple git repo manager with limited remote object proxying, a http back-end and simple cli.
We found that grit demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.