Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
THIS PROJECT IS OPEN FOR MAINTAINERS
Development on the python-social-auth projects has been stagnated for a while, #445 was open a long time ago to discuss this matter and a plan (failed) was presented to fix the situation. For that reason, I'm opening the organization to new maintainers that will have the proper permissions to unstuck development.
Those willing to join, contact me by email with the subject
[PSA Maintainer] <your name>
and please let me know what motivates you to join in such role.
Python Social Auth is an easy to setup social authentication/registration mechanism with support for several frameworks and auth providers.
This is the core component of the python-social-auth ecosystem, it implements the common interface to define new authentication backends to third parties services, implement integrations with web frameworks and storage solutions.
Project documentation is available at http://python-social-auth.readthedocs.org/.
$ pip install social-auth-core
See the CONTRIBUTING.md document for details.
This project follows Semantic Versioning 2.0.0.
This project follows the BSD license. See the LICENSE for details.
This project is maintained on my spare time, consider donating to keep it improving.
FAQs
Python social authentication made simple.
We found that social-auth-core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.