
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@tago-io/cli
Advanced tools
For more information on the latest release notes, please visit the Release Notes section
TagoIO Command Line Tools is a CLI tool that allows you to interact with TagoIO platform and manage your applications. You can use it to deploy, run, trigger, and debug your analysis, as well as to inspect, backup, and configure your devices. You can also export your applications from one profile to another.
To use this tool, you need to install it globally with npm and also install the builder dependency. You also need to generate a tagoconfig.json file for your project and a .tago-lock file for your profile. You can work with multiple environments by using the init and set-env commands.
For more information about the commands and options of this tool, please refer to the Command List section.

Installing the TagoIO Command Line Tools is a straightforward process. Follow these steps to get started:
Preparation: Ensure that Node.js and npm are installed on your machine. If not, refer to the installation guide.
CLI Tool Installation: Open your terminal and run the following command to install the CLI tool globally:
npm install -g @tago-io/cli
Builder Dependency Installation: Next, install the builder dependency using the command:
npm install -g @tago-io/builder
Project Initialization: Initialize your project by generating a tagoconfig.json file. Use the command below and follow the on-screen instructions to provide your credentials or profile-token (available in your TagoIO account):
tagoio init
Profile Token Storage (Optional): To store your profile token in a .tago-lock file, use the tagoio login command. This step also allows you to work with different environments by adding an argument to the command:
tagoio login
List of commands of the CLI Usage:
Options:
Commands:
| Command | Description |
|---|---|
| init [environment] | create/update the config file for analysis in your current folder |
| login [environment] | login to your account and store profile_token in the .tago/tago-lock |
| set-env [environment] | set your default environment from tagoconfig.ts |
| list-env | list all your environment and show current default |
| Analysis | |
| deploy, analysis-deploy [name] | deploy your analysis to TagoIO |
| run, analysis-run [name] | run your TagoIO analysis from your machine. |
| at, analysis-trigger [name] | send a signal to trigger your analysis TagoIO |
| ac, analysis-console [name] | connect to your Analysis Console |
| ad, analysis-duplicate [ID] | duplicate your Analysis |
| am, analysis-mode [name] | change an analysis or group of analysis to run on tago/external |
| Devices | |
| inspect, device-inspector [ID/Token] | connect to your Device Live Inspector |
| info, device-info [ID/Token] | get information about a device and it's configuration parameters |
| dl, device-list | get the list of devices |
| data [ID/Token] | get data from a device |
| bkp, device-backup [ID/Token] | backup data from a Device. Store it on the TagoIO Cloud by default |
| device-type [ID/Token] | change the bucket type to immutable or mutable |
| Profiles | |
| export, app-export | export an application from one profile to another |
When writing up your analysis, make sure you have the following lines at end of the code:
Analysis.use(startAnalysis, { token: process.env.T_ANALYSIS_TOKEN });
If you want to use the Debugger with -D, make sure you have a .swcrc file with sourceMaps activated. This repository contains a .swcrc.example file if you prefer to just copy to your folder.
Managing multiple environments is a breeze with the TagoIO CLI. This feature facilitates seamless alternation between different environments for deployment and analysis management. Here's how you can make the most of it:
To set up a new environment, use the tagoio init command. This will guide you through the necessary steps to establish a fresh environment for your project. Here's how you can do it:
tagoio init
If you are working with multiple environments, switching between them is essential. Use the tagoio set-env command to change your current environment effortlessly. Here's the command to use:
tagoio set-env [environment_name]
Securing your credentials is a critical aspect of working with the TagoIO CLI. The CLI ensures the safe storage of your Profile-Token, which is vital for accessing various functionalities. Here's how the credentials storage works:
When you execute commands like tagoio login or tagoio init, the CLI securely stores your Profile-Token in the current folder accessed by your terminal. Here's a brief on these commands:
tagoio login: This command allows you to log in to your account, storing the profile token in the process.
tagoio login
tagoio init: This command initiates the creation of a new project, during which you will be prompted to enter your credentials, generating a Profile-Token.
tagoio init
The stored Profile-Token is encrypted and saved in a file named .tago-lock.{env}.lock, ensuring the security of your sensitive information.
The tagoconfig.json file serves as the central configuration file for your JavaScript or TypeScript project when working with the TagoIO CLI. This file contains vital information about your analysis, including their IDs and names. Here's how you can set up and utilize the tagoconfig.json file effectively:
To create a tagoconfig.json file, initiate your project using the tagoio init command. This command sets up the necessary structure for your project, including the creation of the tagoconfig.json file.
tagoio init
If you are using the TagoDeploy service, you can configure the URLs for both the API and SSE:
tagoDeployUrl field in the tagoconfig.json file with the URL of your server.tagoDeploySse field in the tagoconfig.json file with the URL of your server.The tagoconfig.json file encapsulates information about your current project, including:
Having a tagoconfig.json file is essential for executing several commands, such as:
tagoio deploy: This command deploys your project to the TagoIO platform.
tagoio deploy
tagoio trigger: Use this command to trigger specific actions or events in your project.
tagoio trigger
tagoio run: This command allows you to run your project locally for testing and development.
tagoio run
TagoIO SDK for JavaScript in the browser and Node.js is released under the Apache-2.0 License.
FAQs
TagoIO Application CLI Node.JS
The npm package @tago-io/cli receives a total of 174 weekly downloads. As such, @tago-io/cli popularity was classified as not popular.
We found that @tago-io/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.