
Research
/Security News
DuckDB npm Account Compromised in Continuing Supply Chain Attack
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
This Rails engine dynamically generates menus.
Primarily developed for Ten Thousand Hours but we are happy to share if anybody finds it useful. It's meant primarily to be used with other tkh gems and the TKH CMS eco-system but overtime we want it to be used individually as well. The latter implementation will be accelerated if some issues and pull requests come in, denoting some interest out there.
It's still embryonic but many improvements to come.
The following things are needed:
For Rails 4.0.0 and above add this line to your application's Gemfile:
gem 'tkh_menus', '~> 0.9'
For prior versions of Rails, use this:
gem 'tkh_menus', '< 0.9'
Then execute:
$ bundle
Import migrations and needed files
$ rake tkh_menus:install
Run the migrations
$ rake db:migrate
And then of course restart your server!
$ rails s
Update the gem:
$ bundle update tkh_menus
Update files, migrations, etc. This is only needed with a new minor version number ( second level from left )
$ rake tkh_menus:update
Run migrations if there are new ones
$ rake db:migrate
Start your server!
$ rails s
The section is located at:
/menus
... and it should work out of the box
Pull requests for new features and bug fixes are welcome.
git checkout -b my-new-feature
)git commit -am 'Added some feature'
)git push origin my-new-feature
)FAQs
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
Security News
The MCP Steering Committee has launched the official MCP Registry in preview, a central hub for discovering and publishing MCP servers.
Product
Socket’s new Pull Request Stories give security teams clear visibility into dependency risks and outcomes across scanned pull requests.