Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Run a few sanity checks on your logical PostgreSQL replica to make sure its the same as the primary.
A tool to compare a PostgreSQL logical replica to its primary. It can help detect data inconsistencies.
These tests assume that id
and updated_at
(or column specified in --lag-column
) columns exist and have indexes for efficient querying and that the table exists on both databases.
Runs row comparisons between primary and replica using two methods:
--rows
) at random between MIN(id)
and MAX(id)
Checks for "replica lag" by comparing MAX(updated_at)
on the given table on both databases.
Checks that the minimum id
and the maximum id
match on both replica and primary. These can drift a little because of replica lag.
Take the sum of the id
column in chunks of 1000 and compare it between databases. This assumes that retrieving rows in bulk is easier than at random and runs faster than the row comparison and can scan more rows.
Counts all the rows using COUNT(lag_column)
to make sure row counts match on both replica and primary. Very slow, since it has to do a full scan (index or table). Adjust --count-before
to count all columns before a timestamp on --lag-column
, or updated_at
by default.
Go throught the table with a step size of MAX(id)
* --step-size=0.01
. The assumption is that if records will be missing, they will be missing in bulk, grouped together.
brew install postgresql
. On Ubuntu, install libpq-dev
.Using virtualenv, pip install -r requirements.txt
Using Pypi, pip install pg-replica-auditor
.
This script requires three arguments:
--primary
, any acceptable Postgres connection string (incl. DSN),--replica
, same as --primary
but for the replica database,Optional arguments:
--exclude-tables
, excludes the comma-separated tables from the scan,--table
, only scans this table,--debug
, will print debugging information,--rows
, will scan this many rows in the row comparisons check,--lag-column
, will use this column for the replica lag check,--show-skipped
, will print the skipped rows in the Last 1000 check,--count-before
, will count all rows in the table created/updated before this timestamp,--step-size
, will decrease the step size for missing sequential records search.Example:
$ pgreplicaauditor --primary=postgres://primary-db.amazonaws.com:5432/my_db --replica=postgres://replica-db.amazonaws.com:5432/my_db --table=immutable_items --lag-column=created_at --count-before="2020-04-06"
FAQs
Run a few sanity checks on your logical PostgreSQL replica to make sure its the same as the primary.
We found that pg-replica-auditor demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.