Remote Code Execution Found in CococaPods

This page summarizes the projects mentioned and recommended in the original post on news.ycombinator.com

InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
  • cocoapods-stats

    Statistics plugin for CocoaPods

  • Not to mention that things like stats (useful for assessing quality) have been broken for years [1].

    This is definitely not meant as a criticism of the CocoaPods team, who have done an amazing job, given that they're working on a volunteer basis, and even had to pay for the infrastructure costs out of pocket.

    It just amazes me that Apple couldn't donate a few thousand dollars to help out such a critical part of their developer ecosystem. It would have been nothing to them.

    [1] https://github.com/CocoaPods/cocoapods-stats/issues/32

  • cdn.cocoapods.org

    The new CDN

  • It would be possible to do this by querying the specs repo https://github.com/CocoaPods/cdn.cocoapods.org. This is what the web-app does.

    I noticed that quite a few pods have more than 1 distinct source when checking the pods used by projects I have worked on. From what I could see source changes were the result of ownership changes, GitHub account name changes, etc.

    So i'm not sure how to distinguish malicious source changes from innocuous ones. Maybe it would be worthwhile to search for source changes that lasted a single release and reverted thereafter.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • Firebase Functions Express Typescript Project Guide Part 1

    1 project | dev.to | 13 May 2024
  • Volt: A Ruby web framework where your Ruby runs on both server and client

    1 project | news.ycombinator.com | 13 May 2024
  • Hanami Shrine - file handling in Hanami

    1 project | dev.to | 13 May 2024
  • Building the DevOps Pipeline

    2 projects | dev.to | 13 May 2024
  • RDS Database Migration Series - Facing The Giant: How we migrated 11 TB database

    2 projects | dev.to | 13 May 2024