
Research
Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.
@pulumi/tls
Advanced tools
The TLS resource provider for Pulumi lets you create TLS keys and certificates in your cloud programs. To use this package, please install the Pulumi CLI first.
This package is available in many languages in the standard packaging formats.
To use from JavaScript or TypeScript in Node.js, install using either npm:
$ npm install @pulumi/tls
or yarn:
$ yarn add @pulumi/tls
To use from Python, install using pip:
$ pip install pulumi_tls
To use from Go, use go get to grab the latest version of the library
$ go get github.com/pulumi/pulumi-tls/sdk/v5
To use from .NET, install using dotnet add package:
$ dotnet add package Pulumi.Tls
The @pulumi/tls package provides a strongly-typed means to build cloud applications that create
and interact closely with TLS resources.
For further information, please visit the TLS provider docs or for detailed reference documentation, please visit the API docs.
node-forge is a JavaScript library that provides a native implementation of TLS, PKI, and various cryptographic utilities. It is more general-purpose compared to @pulumi/tls, which is specifically designed for infrastructure as code scenarios.
pem is a simple library for creating and managing PEM encoded certificates and keys. It provides functionalities similar to @pulumi/tls but is more focused on basic certificate and key management rather than integration with infrastructure as code.
openssl-wrapper is a Node.js wrapper for the OpenSSL command-line tool. It allows you to perform various cryptographic operations, including creating certificates and keys. While it offers similar functionalities, it relies on the OpenSSL binary and is not as tightly integrated with infrastructure as code workflows as @pulumi/tls.
FAQs
A Pulumi package to create TLS resources in Pulumi programs.
The npm package @pulumi/tls receives a total of 283,862 weekly downloads. As such, @pulumi/tls popularity was classified as popular.
We found that @pulumi/tls demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.