
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@jupiterone/graph-cbdefense
Advanced tools
JupiterOne managed integration for Carbon Black Defense.
Learn about the data ingested, benefits of this integration, and how to use it with JupiterOne in the integration documentation.
Install Node.js using the installer or a version manager such as nvm or fnm.
Install dependencies with yarn install
.
Register an account in the system this integration targets for ingestion and obtain API credentials.
cp .env.example .env
and add necessary values for runtime configuration.
When an integration executes, it needs API credentials and any other
configuration parameters necessary for its work (provider API credentials,
data ingestion parameters, etc.). The names of these parameters are defined
by the IntegrationInstanceConfigFieldMap
in src/config.ts
. When the
integration is executed outside the JupiterOne managed environment (local
development or on-prem), values for these parameters are read from Node's
process.env
by converting config field names to constant case. For example,
clientId
is read from process.env.CLIENT_ID
.
The .env
file is loaded into process.env
before the integration code is
executed. This file is not required should you configure the environment
another way. .gitignore
is configured to to avoid commiting the .env
file.
yarn start
to collect datayarn graph
to show a visualization of the collected datayarn j1-integration -h
for additional commandsStart by taking a look at the source code. The integration is basically a set of functions called steps, each of which ingests a collection of resources and relationships. The goal is to limit each step to as few resource types as possible so that should the ingestion of one type of data fail, it does not necessarily prevent the ingestion of other, unrelated data. That should be enough information to allow you to get started coding!
See the SDK development documentation for a deep dive into the mechanics of how integrations work.
See docs/development.md for any additional details about developing this integration.
The history of this integration's development can be viewed at CHANGELOG.md.
FAQs
JupiterOne managed integration for Carbon Black Defense.
The npm package @jupiterone/graph-cbdefense receives a total of 1 weekly downloads. As such, @jupiterone/graph-cbdefense popularity was classified as not popular.
We found that @jupiterone/graph-cbdefense demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.