
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@koala-live/browser
Advanced tools
To start watching files for changes and run a dev server:
yarn dev
You can now navigate to 127.0.0.1:8080
to test your changes. If you wish to automatically open the html page:
yarn dev --open
We push two versions of the sdk: the standalone version and the umd version. The "standalone" version is what typically ships to browsers via CDN and self-installs. The umd version attaches to the window object as well (in a browser environment) but must be manually initialized:
// if the umd script is loaded from CDN directly in the browser, you can find the module attached to `window.KoalaSDK`:
window.KoalaSDK.load({ project })
// or if you import it when using a bundler:
import * as KoalaSDK from '@koala-live/browser'
KoalaSDK.load({ project })
To test the standalone version, you can yarn dev
and navigate to http://localhost:8080/standalone.html?project=cardi-b
aws
cli - follow the latest docs on installing the AWS CLI. Once installed, make sure you've configured it via aws configure
.The Koala SDK is hosted on S3, and fronted by a Cloudflare Worker that acts as our CDN. To push a new version to S3:
yarn deploy
It will push the latest build into the koala-sdk/latest
bucket, as well as an immutable bucket associated with the current git sha: e.g. koala-sdk/e1b323d
FAQs
## Running locally
The npm package @koala-live/browser receives a total of 1 weekly downloads. As such, @koala-live/browser popularity was classified as not popular.
We found that @koala-live/browser demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.