
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@hoprnet/avadosdk
Advanced tools
avadosdk is a tool to make the creation of new avado packages as simple as possible. It helps to initialize and publish in ethereum blockchain
Tools to create your own AVADO compatible packages.
Install straight from github using this command:
npm i -g git+https://github.com/AvadoDServer/AVADOSDK.git
mkdir mypackage
cd mypackage
avadosdk init
(then answer these questions)
? AVADO package name mypackage.avado.dappnode.eth
? Version 0.0.1
? Description mypackageavado.dappnode.eth description
? Author sponnet
? License GLP-3.0
Now you have a package template
try building it - connect to your AVADO (for IPFS access) and type
avadosdk build
✔ Create release dir
✔ Copy files and validate
✔ Build docker image
✔ Save and compress image
✔ Upload avatar to IPFS
✔ Upload image to IPFS
✔ Upload manifest to IPFS
✔ Save upload results
package built and uploaded
Manifest hash : /ipfs/QmZ1xDukvh2gimJ3JbSrn7MvsibA9X2QuRRBGzFwFeNo9E
now go to your AVADO http://my.avado/#/installer and paste the IPFS hash in the search field above.
now you can install your package and test it out !
It's running
Success !
FAQs
avadosdk is a tool to make the creation of new avado packages as simple as possible. It helps to initialize and publish in ethereum blockchain
We found that @hoprnet/avadosdk demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.