
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
github.com/HansRobo/ssl_gui_test
frontend
ディレクトリに移動します:
cd frontend
依存関係をインストールします:
npm install
開発サーバーを起動します:
npm run serve
ESLintを使用してコードをチェックします:
npm run lint
backend
ディレクトリに移動します:
cd backend
依存関係をインストールします:
go mod tidy
バックエンドサーバーを起動します:
go run main.go
GolangCI-Lintを使用してコードをチェックします:
golangci-lint run
http://localhost:8080
にアクセスします。F1
キーを押して、Remote-Containers: Open Folder in Container...
を選択します。frontend
ディレクトリに移動します:
cd frontend
Huskyをインストールします:
npx husky install
Pre-commitフックを設定します:
npx husky add .husky/pre-commit "npm run lint"
.github/workflows/lint.yml
ファイルを作成し、以下の内容を追加します:
name: Lint
on:
push:
branches:
- main
pull_request:
branches:
- main
jobs:
lint:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v2
- name: Set up Node.js
uses: actions/setup-node@v2
with:
node-version: '14'
- name: Install dependencies
run: npm install
- name: Run ESLint
run: npm run lint
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.