The #NodeJS #Axios maintainer gave a few more details about how they were targeted by someone impersonating a larger company who managed to grab their browser’s cookie store. There’ve been a lot of speculation about how it could have been stopped but realistically we’re talking about things like supporting projects so there can realistically be n>1 person in the release process:

https://github.com/axios/axios/issues/10604#issuecomment-4169063636

https://github.com/axios/axios/issues/10636

[email protected] and [email protected] are compromised · Issue #10604 · axios/axios

more details: https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan Most likely, a maintainer's GitHub and npm accounts are compromised as these iss...

GitHub

Master the data flow: Discover step-by-step how Axios processes your POST requests and handles promises. 🚀EN

Domina el flujo de datos: Descubre paso a paso cómo Axios procesa tus peticiones POST y maneja promesas. 🚀ES

#programming #coding #programación #code #webdevelopment #devs #softwaredevelopment #axios #npm #nodejs

🚀 How to Install and Run Rocket.Chat on #Debian #VPS This article describes how to install and run Rocket.Chat on Debian VPS.
What is Rocket.Chat?
Rocket.Chat is an open-source communication platform designed for team collaboration and messaging, similar to Slack or Microsoft Teams. It offers a flexible, self-hosted alternative for businesses, communities, and developers who want full control ...
Continued 👉 https://blog.radwebhosting.com/install-and-run-rocket-chat-on-debian-vps/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #selfhosted #certbot #selfhosting #rocketchat #nodejs #nginx

Security Bug Bounty Program Paused Due to Loss of Funding

https://mander.xyz/post/49882157

Security Bug Bounty Program Paused Due to Loss of Funding - Mander

Lemmy

NodeJS: Security Bug Bounty Program Paused Due to Loss of Funding

https://nodejs.org/en/blog/announcements/discontinuing-security-bug-bounties

#nodejs

Node.js — Security Bug Bounty Program Paused Due to Loss of Funding

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

The #Nodejs project's security bug bounty program is being paused due to the discontinuation of its external funding source 😞

https://nodejs.org/en/blog/announcements/discontinuing-security-bug-bounties

Node.js — Security Bug Bounty Program Paused Due to Loss of Funding

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

🐛 Security Bug Bounty Program Paused Due to Loss of Funding
at @nodejs.org @nodejs
#NodeJS #webdev #InternetBugBounty
https://nodejs.org/en/blog/announcements/discontinuing-security-bug-bounties

📍 Node.js drops bug bounty rewards after external funding dries up.

A real hit to its security incentives → https://socket.dev/blog/node-js-drops-bug-bounty-rewards-funding-dries-up #nodejs #javascript

Node.js Drops Bug Bounty Rewards After Funding Dries Up - So...

Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Socket

How to Install #Directus on #AlmaLinux #VPS

Here's a step-by-step guide detailing how to install Directus on AlmaLinux VPS.
What is Directus?
Directus is an open-source #headless #CMS and data platform that allows you to manage and interact with your database through a RESTful API or GraphQL API. It provides a modern, ...
Continued 👉 https://blog.radwebhosting.com/install-directus-on-almalinux-vps/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #npm #cmsapps #installguide #opensource #vpsguide #letsencrypt #nodejs #selfhosting #postgresql #selfhosted #contentmanagement