
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
An app for tagging and organizing large numbers of photos efficiently.
This arose out of my Pho image viewer (Pho on GitHub). It started to get unwieldy adding ever more tagging features to what was intended as just a fast, light image viewer.
Metapho is intended as a lightweight, flexible way of organizing large numbers of photos. It uses text files, not a proprietary database, so you're not locked down to one app or a proprietary database, and you can view your tags databases at any time, or edit them in a text editor if you should ever want to.
Metapho can be driven entirely from the keyboard: you should be able to do everything you need without moving your hands to the mouse, though you can use the mouse if you find that easier.
It depends on PyGTK, but not on gnome or any other desktop services.
It also install three scripts:
notags:
Examine the current directory recursively and tell you about files and
directories that still need to be tagged. Run it at the root of
an image directory that might have untagged subdirectories.
fotogr:
Search for files with particular tags.
photoshare:
Manage files tagged with "share".
Metapho is available on PyPi,
so you can install it as pip install metapho
(though of course the PyPI version won't always have the
very latest features and bug fixes).
Read the Metapho Documentation for more information on both the app and the API of the classes inside it.
FAQs
Image viewer and tagger
We found that metapho demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.