Socket
Socket
Sign inDemoInstall

@contrast/agent

Package Overview
Dependencies
228
Maintainers
8
Versions
276
Alerts
File Explorer

Advanced tools

Install Socket

Detect and block malicious and high-risk dependencies

Install

    @contrast/agent

Node.js security instrumentation by Contrast Security


Version published
Maintainers
8
Created

Readme

Source

Contrast Security Node.js Agent

This package will enable instrumentation of your Node.js application for security anaylsis and runtime protection by ContrastSecurity.com.

Unlike legacy application security testing solutions, Contrast produces accurate results without dependence on application security experts. Accuracy comes from Contrast's patented Deep Security Instrumentation technology, which integrates the most effective elements of Interactive (IAST), Static (SAST), and Dynamic (DAST) application security testing technology, software composition analysis (SCA), and configuration analysis, and delivers them directly to applications.

Contrast produces a continuous stream of accurate vulnerability and compliance risk information whenever and wherever software is run. Development, QA and Security teams get results as they develop and test software, enabling them to find and fix security flaws early in the software lifecycle, when they are easiest and cheapest to remediate.

Getting Started

Existing Contrast Node.js agent users should install and update the Contrast Node.js agent from npm. Auto-update for the Node.js agent is no longer supported. The Contrast Node.js agent follows semantic versioning (major.minor.patch).

An API key, provided by Contrast Security, is required for the agent to function.

Ensure you have installed the latest LTS (Long Term Support) version of Node.js

To install from npm using the command line (run from the app root directory):

$ npm install @contrast/agent

Usage

    Usage: node -r @contrast/agent app-main.js [agent arguments] -- [app arguments]

    Options:

        -h, --help           output usage information
        -V, --version        output the version number
        -c, --config <path>  path to agent config file

The agent expects that the contrast_security.yaml configuration file exists in the application's root directory (where the package.json file usually resides). The minimum required contrast_security.yaml setup should look something like this:

api:
  url: https://app.contrastsecurity.com
  user_name: contrast_user
  api_key: demo
  service_key: demo
PropertyDescription
api.api_keyOrganization's API key
api.user_nameContrast user account ID (In most cases, this is your login ID)
api.service_keyContrast user account service key
api.urlAddress of the Contrast installation you would like your agent to report to

For detailed installation and configuration instructions, see the Node.js Agent documentation.

Keywords

FAQs

Last updated on 22 Apr 2020

Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc