Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
amp-toolbox-cli
Advanced tools
The AMP Toolbox command line interface consists of a Node.js program called amp-toolbox-cli
that can be run from a Windows, macOS, of UNIX-compatible command line environment. This way, AMP Toolbox can easily be integrated into a command line build process.
Supported commands:
amp-toolbox-cli
version.Displays the help menu, listing all available commands:
$ ./amp-toolbox-cli help
Pass a command to get more information about this specific command
./amp-toolbox-cli help [command]
Example:
$ ./amp-toolbox help update-cache
Prints the current version
Example:
$ ./amp-toolbox version
Prints the current version of the AMP runtime.
Example:
$ ./amp-toolbox runtime-version
### update-cache
Uses the [AMP update-cache API](https://developers.google.com/amp/cache/update-cache) to update documents stored in AMP Caches.
It requires the public and private keys to be generated, as [described on the documentation](https://developers.google.com/amp/cache/update-cache#rsa-keys). Only the private key is required to generate the cache invalidation URLs, but the public key must be made available to the AMP Caches, as described in the [guidelines](https://developers.google.com/amp/cache/update-cache#update-cache-guidelines).
By default, the application will look for the private key on a file called `privateKey.pem`, on the current working directory.
```shell
$ ./amp-toolbox-cli update-cache https://www.example.com/
Optionally, use the --privateKey
parameter to specify the path for the private key.
$ ./amp-toolbox-cli update-cache https://www.example.com/ --privateKey /path/to/private-key.pem
FAQs
A Command Line Interface (CLI) for amp-toolbox
We found that amp-toolbox-cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.