
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@serverless/enterprise-plugin
Advanced tools
This is a Serverless Framework plugin which helps you use advanced monitoring, tracing and governance features via the Serverless Platform.
The Plugin automatically wraps your functions and instruments them with the Serverless Platform's monitoring, alerting, logging and tracing features.
This isn't published to npm yet, so first clone this repo.
Next, in your Serverless Framework service's package.json
, reference it on your system as a development dependency, like this:
"devDependencies": {
"serverless-platform-plugin": "file:../../platform-plugin"
}
Make sure to update the path to point to the correct directory.
In your Serverless Framework service, run npm i
Then add the plugin to your serverless.yml
, like this:
plugins:
- serverless-platform-plugin
For collection logs to the platform, you need to set some configuration in your serverless.yml
custom:
platform:
collectLambdaLogs: true
# Note: Automatic configuration for collecting API logs
# is only possible on never before deployed apps for
# right now. his is a limitation of API Gateway and
# CloudFormation at the moment. We are looking for options.
collectApiLogs: true
Currently, the serverless-sdk
is within this project. On deployment, this plugin copies a bundled and compressed version of the serverless-sdk
into your Service package before it's uploaded.
If you are updating the serverless-sdk
, afterwards be sure to cd into the sdk-js
folder and run npm run build
to create a bundled version in sdk-js/dist
.
On the next deployment, the new sdk
will be included.
FAQs
The Serverless Dashboard plugin
We found that @serverless/enterprise-plugin demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.