Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
If you are viewing this README on GitHub, please be aware that placement
development happens on OpenStack git <https://opendev.org/openstack/placement/>
_ and OpenStack gerrit <https://review.opendev.org>
_.
.. image:: https://governance.openstack.org/tc/badges/placement.svg :target: https://governance.openstack.org/tc/reference/tags/index.html
OpenStack Placement provides an HTTP service for managing, selecting, and claiming providers of classes of inventory representing available resources in a cloud.
To learn how to use Placement's API, consult the documentation available online at:
Placement API Reference <https://docs.openstack.org/api-ref/placement/>
__For more information on OpenStack APIs, SDKs and CLIs in general, refer to:
OpenStack for App Developers <https://www.openstack.org/appdev/>
__Development resources for OpenStack clouds <https://developer.openstack.org/>
__To learn how to deploy and configure OpenStack Placement, consult the documentation available online at:
OpenStack Placement <https://docs.openstack.org/placement/>
__In the unfortunate event that bugs are discovered, they should be reported to the appropriate bug tracker. If you obtained the software from a 3rd party operating system vendor, it is often wise to use their own bug tracker for reporting problems. In all other cases use the master OpenStack bug tracker, available at:
Bug Tracker <https://bugs.launchpad.net/placement>
__File new Bug <https://bugs.launchpad.net/placement/+filebug>
__For information on how to contribute to Placement, please see the contents of CONTRIBUTING.rst.
Further developer focused documentation is available at:
Official Placement Documentation <https://docs.openstack.org/placement/>
__FAQs
Resource provider inventory usage and allocation service
We found that openstack-placement demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.