
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
Manage your Alpaca portfolio from the comfort of your terminal!
Good when you want to trade inconspicuously (at work, at school, in a boring meeting), or if you're just a nerd like me.
You are responsible for your Alpaca account, and for using this software responsibly. Make sure that you know what a command will do before you run it. This tool is currently being developed only for my own personal use and amusement, and is distributed in the hope that others might find it interesting. It does not come with safety features and has no guarantees of correctness.
Make sure you have Node.js installed, and then run:
npm install -g alpaca-cli
This will install the alpaca command globally.
Get an api key from https://alpaca.markets, and configure your alpaca cli:
alpaca configure --id=<key-id> --secret=<secret-key>
alpaca <command>
commands:
configure configure your alpaca cli installation
buy buy a stock
sell sell a stock
report display a report of your current portfolio
Run alpaca help <command> for help with a specific command.
FAQs
Manage your Alpaca portfolio from the comfort of your terminal!
We found that alpaca-cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.