
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@techdocs/cli
Advanced tools
Check out the TechDocs README to learn more.
WIP: This cli is a work in progress. It is not ready for use yet. Follow our progress on the Backstage Discord under #docs-like-code or on our GitHub Milestone.
Install the techdocs-cli:
npm install -g @techdocs/cli
In this example we'll show you how to build the example docs shipped with techdocs-container.
# In this example we'll use a 'projects' folder in your home directory to check out backstage, but feel free to pick whatever folder you prefer.
cd ~/projects
git clone https://github.com/backstage/techdocs-container.git
cd ~/projects/techdocs-container/mock-docs
# To get a view of your docs in Backstage, use:
npx techdocs-cli serve
# To view the raw mkdocs site (without Backstage), use:
npx techdocs-cli serve:mkdocs
If you run npx techdocs-cli serve
you should have a localhost:3000
serving TechDocs in Backstage, as well as localhost:8000
serving Mkdocs (which won't open up and be exposed to the user).
If running npx techdocs-cli serve:mkdocs
you will have localhost:8000
exposed, serving Mkdocs.
Happy hacking!
Deploying the Node packages to NPM happens automatically on merge to main
through GitHub Actions. The package is published to @techdocs/cli
in NPM. Just bump the version number in the package.json file and create a pull request. It will deploy when merged.
FAQs
Utility CLI for managing TechDocs sites in Backstage.
The npm package @techdocs/cli receives a total of 21,723 weekly downloads. As such, @techdocs/cli popularity was classified as popular.
We found that @techdocs/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.