Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Statina is a visualisation tool for the data produced by the Fluffy pipeline running WisecondorX to analyze NIPT.
git clone https://github.com/Clinical-Genomics/statina
cd statina
pip install -r requirements.txt -e .
The CLI is intended for development/testing purpose only. To run in a production setting please refer to documentation for suggestions how.
Once installed, you can set up Statina by running a few commands using the included command line interface. Given you have a MongoDB server listening on the default port (27017), this is how you would set up a fully working Statina demo:
statina load batch --result-file statina/tests/fixtures/valid_fluffy.csv
Settings can be used by exporting the environment variables: DB_NAME
, DB_URI
, HOST
, PORT
This will set up an instance of Statina with a database called statina-demo
. Now run
statina serve --reload
and play around with the interface.
Statina can also run as a container. The image is available on Docker Hub or can be build using the Dockerfile provided in this repository.
To build a new image from the Dockerfile use the commands: docker build -t statina .
To run the image use the following command: docker run --name statina statina statina
To remove the container, type: docker rm statina
Statina is using github flow release model as described in our development manual.
Opening pull requests in Statina repository will enable a Github Action to build containers and publish to statina-stage dockerhub with each commit.
Two tags will be published: one with the name of the branch and another tagged "latest".
Steps to test current branch on staging:
ssh firstname.lastname@cg-vm1.scilifelab.se
sudo -iu hiseq.clinical
ssh localhost
If you made changes to internal app : systemctl --user restart statina.target
Your branch should be deployed to staging at https://statina-stage.scilifelab.se
If for some reason you cannot access the application at given address, check status of the container: systemctl --user status statinaApp.service
Use update-statina.sh
script to update production both on Hasta and CGVS.
Please follow the development guide and servers
repo when doing so. It is also important to keep those involved informed.
The Statina database is a Mongo database consisting of following collections:
The database is loaded through the CLI with data generated by the FluFFyPipe
FAQs
NIPT data storage and visualisation
We found that statina demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.