Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Umlaut is software for libraries (the kind with books).
It could be described as a front-end layer on top of an existing OpenURL knowledge base. But it's actually quite a bit more than that.
It could also be described as: a just-in-time aggregator of "last mile" specific-citation services, taking input as OpenURL, and providing both an HTML UI and an api suite for embedding Umlaut services in other products.
Umlaut's role is to provide the user with services that apply to the item of interest. And services provided by various different products: including as a major target, your OpenURL Knowledge Base, but also including other products. Services provided by the hosting institution, licensed by the hosting institution, as well as free services the hosting institution wishes to advertise/recommend to it's users.
Umlaut strives to supply links that take the user in as few clicks as possible to the service listed, without ever listing 'blind links' that you first have to click on to find out whether they are available. Umlaut pre-checks things when neccesary to only list services, with any needed contextual info, such that the user knows what they get when they click on it. Save the time of the user.
Umlaut is distributed as a ruby Rails engine gem. It's a very heavyweight engine, the point of distro'ing as a gem is to make it easy to keep local config/customization/enhancement seperate from distro, not so much to let you 'mix in' Umlaut to an already existing complex app.
For complete step-by-step install instructions suitable even for the neophyte, see: https://github.com/team-umlaut/umlaut/wiki/Installation.
The Rails/Umlaut super-concise expert summary is:
Rails 3.2+ (Rails 4.1+ highly recommended, Rails 3's days are numbered),
ruby 1.9.3+ (Consider ruby 2.0 or 2.1, 1.9.3's days are numbered)
$ gem install umlaut
Then run the umlaut app generator: $ umlaut my_new_app
$ rails generate umlaut:install
set up your db in config/databases.yml and run rake db:migrate
configuration in ./config/umlaut_services.yml
and ./app/controllers/umlaut_controller.rb
Umlaut uses multi-threaded concurrency in a way incompatible with development-mode class reloading. You need cache_classes=false even in dev, the Umlaut install generator changes this for you.
Some Umlaut services adapters are sufficiently complicated or are on different release cycles from the core code that they merit their own gems. Generally, you will need to include these gems in your application's Gemfile in order to get the described functionality.
Add on | Description |
---|---|
umlaut-primo | Umlaut services to provide full text service responses, holdings, etc. from the Primo discovery solution. |
umlaut_borrow_direct | Links and embedded availability from BorrowDirect consortial borrowing service |
Some test coverage not yet complete, but we're trying to improve. Don't trust if all tests pass everythings good, but if tests fail, that's an unacceptable commit. Try to add tests with new features, although we understand when nobody can figure out a good way to test (esp our legacy architecture).
Run tests with rake test
.
Tests are with plain old Test::Unit, please.
Tests use the vcr gem where appropriate. See ./test/support/test_with_cassette
.
gem skeleton was created with rails plugin new
, which creates a dummy app
that tests are run in context of, at ./test/dummy
.
The vcr gem is used to record HTTP transactions for tests.
There are some helpful methods for setting up and asserting in tests in Umlaut::TestHelp, which are used in Umlaut itself and can also be used in local apps or Umlaut plugins.
See also: https://github.com/team-umlaut/umlaut/wiki/Developing
https://github.com/team-umlaut/umlaut/
You can join the umlaut listserv at: https://groups.google.com/forum/#!forum/umlaut-software
FAQs
Unknown package
We found that umlaut demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.