Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
opentelemetry-instrumentation-action_view
Advanced tools
The ActionView instrumentation is a community-maintained instrumentation for the ActionView portion of the Ruby on Rails web-application framework.
Install the gem using:
gem install opentelemetry-instrumentation-action_view
gem install opentelemetry-instrumentation-rails
Or, if you use bundler, include opentelemetry-instrumentation-action_view
in your Gemfile
.
To use the instrumentation, call use
with the name of the instrumentation:
OpenTelemetry::SDK.configure do |c|
c.use 'OpenTelemetry::Instrumentation::Rails'
c.use 'OpenTelemetry::Instrumentation::ActionView'
end
Alternatively, you can also call use_all
to install all the available instrumentation.
OpenTelemetry::SDK.configure do |c|
c.use_all
end
Example usage can be seen in the ./example/trace_request_demonstration.ru
file here
ActionView instrumentation uses ActiveSupport notifications and in the case when a subscriber raises in start method an unclosed span would break successive spans ends. Example:
class CrashingEndSubscriber
def start(name, id, payload)
raise 'boom'
end
def finish(name, id, payload) end
end
::ActiveSupport::Notifications.subscribe('render_template.action_view', CrashingStartSubscriber.new)
The opentelemetry-instrumentation-action_view
gem source is on github, along with related gems including opentelemetry-api
and opentelemetry-sdk
.
The OpenTelemetry Ruby gems are maintained by the OpenTelemetry Ruby special interest group (SIG). You can get involved by joining us on our GitHub Discussions, Slack Channel or attending our weekly meeting. See the meeting calendar for dates and times. For more information on this and other language SIGs, see the OpenTelemetry community page.
The opentelemetry-instrumentation-action_view
gem is distributed under the Apache 2.0 license. See LICENSE for more information.
FAQs
Unknown package
We found that opentelemetry-instrumentation-action_view demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.