
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
github.com/Excoriate/daggerverse/module-template
A simple Dagger place the description of the module here
Through the Dagger CLI, or by using it directly within your module, you can configure the following options:
ctr
: The container to use as a base container. If not specified, a new container is created.version
: The version of the Go image to use. Defaults to latest
.image
: The Go image to use. Defaults to golang:alpine
.{{.module_name_pkg}} // main module
├── .gitattributes
├── .gitignore
├── LICENSE
├── README.md
├── apis.go
├── cloud.go
├── commands.go
├── common.go
├── config.go
├── dagger.json
├── examples // Sub modules that represent examples of the module's functions with each SDK
│ └── go
│ ├── .gitattributes
│ ├── .gitignore
│ ├── dagger.json
│ ├── go.mod
│ ├── go.sum
│ ├── main.go
│ └── testdata
│ └── common
│ ├── README.md
│ └── test-file.yml
├── go.mod
├── go.sum
├── main.go
└── tests // Sub module that represent tests of the module's functions
├── .gitattributes
├── .gitignore
├── dagger.json
├── go.mod
├── go.sum
├── main.go
└── testdata
└── common
├── README.md
└── test-file.yml
NOTE: This structure comes out of the box if it's generated through Daggy. Just run
just create <module-name>
and you'll get the structure.
Command or functionality | Command | Example | Status |
---|---|---|---|
Add your feature here | run | dagger call <my function> | ✅ |
Place the description of the module here
List all the functions available in the module:
# enter into the module's directory
cd module-template
# list all the functions available in the module
dagger develop && dagger functions
Call a function:
# call a function
# dagger call <function-name> [arguments]
dagger call github.com/excoriate/daggerverse/module-template@version <function-name> [arguments]
This module includes a testing module that aims to test the functionality of the ModuleTemplate module. The tests are written in Go and can be run using the following command:
## Run the tests using the just command
just test module-template
If you'd like to contribute, mostly we use Just to automate tasks and Nix to manage the development environment. You can use the following commands to get started:
# initialize the pre-commit hooks
just init
# run CI or common things locally
just golint module-template
# run the tests
just test module-template
# Run the entire CI tasks locally
just cilocal module-template
Additionally, this module brings a new Daggerverse functionality that allows to automatically generate the module's documentation using an special (sub) module called {{.module_name_pkg}}/examples/sdk. This module contains a set of examples hat demonstrate how to use the module's functions.
To generate the documentation
It's important to notice that each example function in order to be rendered in the documentation, it must be preprocessed by module's name, in this case (camelCase) module-template
.
NOTE: The
just
command entails the use of the Justfile for task automation. If you don't have it, don't worry, you just need Nix to run the tasks using thedev-shell
built-in command:nix develop --impure --extra-experimental-features nix-command --extra-experimental-features flakes
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.