data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@nathf/puppeteer-healthcheck
Advanced tools
Puppeteer Healthcheck is a simple tool wrapped over puppeteer to check page and critical asset status'.
Puppeteer Healthcheck is a tool wrapped over puppeteer to check page and critical asset status'.
Often post deploy we want to check our site/app has been deployed sucessfully. We would want to ensure the web server is responding, critical assets and certain DOM elements exists post deploy.
Node requirements:
NPM
yarn add global @nathf/puppeteer-healthcheck
# or if you prefer NPM
npm i -g @nathf/puppeteer-healthcheck
Docker
docker pull nathf/puppeteer-healthcheck
Example command with config
puppeteer-healthcheck --config healthcheck.config.js
uri: string
Valid URI to check
wait: number
Milliseconds to wait before requesting the URI
assetRegex: string[]
List of regex strings to match asset URLs
e.g.
assetRegex: [
'script-(.+)\.js',
'style-(.+)\.css'
]
screenshots: Screenshot[]
A screenshot object consists of:
These options are referenced from the official Puppeteer Docs
path: string
: absolute path to save the screenshottype: string
: Specify screenshot type, can be either jpeg
or png
. Defaults to 'png'.quality: number
: The quality of the image, between 0-100. Not applicable to png images.fullPage: boolean
: When true, takes a screenshot of the full scrollable page. Defaults to false
.clip: Object
: An object which specifies clipping region of the page. Should have the following fields:
x: number
: x-coordinate of top-left corner of clip areay: number
: y-coordinate of top-left corner of clip areawidth: number
: width of clipping areaheight: number
: height of clipping areaomitBackground: boolean
: Hides default white background and allows capturing screenshots with transparency. Defaults to false.viewport: Object
Referenced from Puppeteer docs
width: number
: page width in pixels.height: number
page height in pixels.deviceScaleFactor: numer
: Specify device scale factor (can be thought of as dpr). Defaults to 1
.isMobile: boolean
: Whether the meta
viewport tag is taken into account. Defaults to false
.hasTouch: boolean
: Specifies if viewport supports touch events. Defaults to false
isLandscape: boolean
: Specifies if viewport is in landscape mode. Defaults to false
.A sample config checking the GitHub login page, checking their hashed css and js and taking screenshots at various sizes.
// healthcheck.config.js
module.exports = {
uri: 'https://github.com/login',
assetRegex: [
'github-(.+)\.js',
'github-(.+)\.css',
],
screenshots: [
{
path: `${__dirname}/desktop.png`,
viewport: {
width: 800,
height: 300
}
},
{
path: `${__dirname}/fullpage.png`,
fullPage: true
},
{
path: `${__dirname}/narrow.png`,
viewport: {
width: 375,
height: 667
}
}
]
}
Results in the following output:
FAQs
Puppeteer Healthcheck is a simple tool wrapped over puppeteer to check page and critical asset status'.
We found that @nathf/puppeteer-healthcheck demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.