data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@janus-idp/backstage-plugin-acr
Advanced tools
The Azure Container Registry (ACR) plugin displays information about your container images available in the Azure Container Registry.
The Azure Container Registry (ACR) plugin displays information about your container images available in the Azure Container Registry.
Run the following command to install the ACR plugin:
yarn workspace app add @janus-idp/backstage-plugin-acr
Set the proxy to the desired ACR server in the app-config.yaml
file as follows:
# app-config.yaml
proxy:
endpoints:
'/acr/api':
target: 'https://mycontainerregistry.azurecr.io/acr/v1/'
changeOrigin: true
headers:
# If you use Bearer Token for authorization, please replace the 'Basic' with 'Bearer' in the following line.
Authorization: 'Basic ${ACR_AUTH_TOKEN}'
# Change to "false" in case of using self hosted artifactory instance with a self-signed certificate
secure: true
Set the authorization using one of the following options:
Basic authorization:
echo printf '<username>:<password>' | base64
in a terminal to convert the credentials into a basic token.ACR_AUTH_TOKEN
in environment variables.OAuth2: - Generate bearer access token using the process described in Authenticate with an Azure Container Registry.
One method is to generate a bearer token using your basic authorization token, i.e.
curl --location 'https://<yourregistry>.azurecr.io/oauth2/token?scope=repository%3A*%3A*&service=<yourregistry>.azurecr.io' \
--header 'Authorization: Basic <basic_token>'
Set the generated token as ACR_AUTH_TOKEN
in environment variables. Make sure to replace the Basic
in the app-config.yaml
with Bearer
Enable an additional tab on the entity view page using the packages/app/src/components/catalog/EntityPage.tsx
file as follows:
/* highlight-add-start */
import { AcrPage, isAcrAvailable } from '@janus-idp/backstage-plugin-acr';
/* highlight-add-end */
const serviceEntityPage = (
<EntityLayout>
// ...
{/* highlight-add-start */}
<EntityLayout.Route
if={e => Boolean(isAcrAvailable(e))}
path="/acr"
title="ACR"
>
<AcrPage />
</EntityLayout.Route>
{/* highlight-add-end */}
</EntityLayout>
);
Annotate your entity using the following annotations:
metadata:
annotations:
'azure-container-registry/repository-name': `<REPOSITORY-NAME>',
ACR is a front-end plugin that enables you to view information about the container images from your Azure Container Registry in Backstage.
Open your Backstage application and select a component from the Catalog page.
Go to the ACR tab.
The ACR tab in the Backstage UI contains a list of container images and related information, such as TAG, CREATED, LAST MODIFIED, and MANIFEST.
FAQs
The Azure Container Registry (ACR) plugin displays information about your container images available in the Azure Container Registry.
The npm package @janus-idp/backstage-plugin-acr receives a total of 18 weekly downloads. As such, @janus-idp/backstage-plugin-acr popularity was classified as not popular.
We found that @janus-idp/backstage-plugin-acr demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.