
Security News
Nx npm Packages Compromised in Supply Chain Attack Weaponizing AI CLI Tools
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.
The purpose of this utility is to drain documents from Elasticsearch nodes in an AutoScaling Group.
This will help you do Elasticsearch node replacement while keeping the cluster healthy. This is useful if you want to change the instance type of your nodes, or if you use custom AMIs and need to rollout a new AMI.
Consider the following deployment procedure:
_id
(s) of those instances$ gem install elasticsearch-drain
$ drain asg --asg="test-asg-0" --region="us-east-1" --host="localhost:9200"
Install all dependencies:
gem install bundler
bundle install
To enable the tests that will hit the AWS APIs pass ALLOW_DISABLED_VCR=true
Run test tests (unit and style):
rake
Or on a tight loop with guard:
bundle exec guard
If you need to make a new http request or refresh the fixtures you will need to start a test cluster.
By default the test cluster install is version 1.7.2
, this can be changed by setting the ES_VERSION
enviroment variable.
Install and Start the Cluster:
rake elasticsearch:install elasticsearch:start
Run the tests:
rake test
Stop the Cluster:
rake elasticsearch:stop
And, to wrap all that up:
rake refresh_fixtures
git checkout -b my-new-feature
)git commit -am 'Add some feature'
)git push origin my-new-feature
)FAQs
Unknown package
We found that elasticsearch-drain demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.
Security News
CISA’s 2025 draft SBOM guidance adds new fields like hashes, licenses, and tool metadata to make software inventories more actionable.
Security News
A clarification on our recent research investigating 60 malicious Ruby gems.