
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
os-refresh-config
Advanced tools
.. image:: https://governance.openstack.org/tc/badges/os-refresh-config.svg :target: https://governance.openstack.org/tc/reference/tags/index.html
.. Change things from this point on
os-refresh-config uses dib-run-parts to run scripts in a
pre-defined set of directories::
/opt/stack/os-config-refresh/pre-configure.d /opt/stack/os-config-refresh/configure.d /opt/stack/os-config-refresh/post-configure.d /opt/stack/os-config-refresh/migration.d /opt/stack/os-config-refresh/error.d
/opt/stack/os-config-refresh is the default base directory. You can
set OS_REFRESH_CONFIG_BASE_DIR environment variable to override the
default one.
Its intended purpose is to separate scripts execution into 4 phases:
It runs through all the phases above to ensure configuration is applied and enabled on a machine. It will run the scripts in error.d and then exit with a non-zero exit status if any phase has a problem. The scripts in each phase should not depend on each other having worked properly.
Note: Earlier versions of os-refresh-config ran migration before post-configure. This was an oversight in the initial design, as migrations are intended to be online migrations after the host is fully configured.
For things which must happen while the service is quiesced, that should be done in the post-configure scripts which control the service state.
FAQs
Refresh system configuration
We found that os-refresh-config demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.