
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@builder.io/ai-shell
Advanced tools
A CLI that converts natural lagnuage to shell commands.
Inspired by Gitbhub Copilot X CLI, but open source for everyone.
The minimum supported version of Node.js is v14
Install ai shell:
npm install -g @builder.io/ai-shell
Retrieve your API key from OpenAI
Note: If you haven't already, you'll have to create an account and set up billing.
Set the key so ai-shell can use it:
ai-shell config set OPENAI_KEY=<your token>
This will create a .ai-shell
file in your home directory.
?ai <prompt>
For example:
?ai list all log files
Then you will get an output like this, where you can choose to run the suggested command, revise the command via a prompt, or cancel:
◇ Your script:
│
│ find . -name "*.log"
│
◇ Explanation:
│
│ 1. Searches for all files with the extension ".log" in the current directory and any subdirectories.
│
◆ Run this script?
│ ● ✅ Yes (Lets go!)
│ ○ 📝 Revise
│ ○ ❌ Cancel
└
Check the installed version with:
ai-shell --version
If it's not the latest version, run:
npm update -g @builder.io/ai-shell
FAQs
A CLI that converts natural language to shell commands.
The npm package @builder.io/ai-shell receives a total of 0 weekly downloads. As such, @builder.io/ai-shell popularity was classified as not popular.
We found that @builder.io/ai-shell demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.