
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@serverless/enterprise-plugin
Advanced tools
This is a Serverless Framework plugin which helps you use advanced monitoring, tracing and governance features via Serverless Enterprise.
The Plugin automatically wraps your functions and instruments them with Serverless Enterprise's monitoring, alerting, logging and tracing features.
Install the plugin via NPM
npm install @serverless/enterprise-plugin
Then add the plugin to your serverless.yml
, like this:
plugins:
- '@serverless/enterprise-plugin'
Serverless Enterprise ships with the following safeguards by default:
To disable Serverless Safeguards, add this to your configuration:
custom:
safeguards: false
Serverless Enterprise automatically aggregates logs. To disable them, set the following options:
custom:
enterprise:
collectLambdaLogs: false
You can install the latest versions from the master branch by installing the next
tag:
npm install @serverless/enterprise-plugin@next
The project is transpiled with babel, so run npm run build
before installing it
Currently, the serverless-sdk
is within this project. On deployment, this plugin copies a
bundled and compressed version of the serverless-sdk
into your Service package before it's
uploaded.
If you are updating the serverless-sdk
, ensure you run npm run build
to rebuild it too
On the next deployment, the new sdk
will be included.
FAQs
The Serverless Dashboard plugin
We found that @serverless/enterprise-plugin demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.