
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
artifactory-registry
Advanced tools
Tested only on MacOS.
CLI for set up JFrog Artifactory with scope in NPM config.
You don't need to install it. Instead you will use npx
.
init
Go to the root path of the project and initialize the tool:
$ npx artifactory-registry init
That command create artifactory.json
file:
{
"scope": "my-scope",
"host": "http://localhost:8081",
"repositoryName": "my-project.npm.dev"
}
Configure artifactory.json
using your JFrog Artifactory NPM configuration.
add
Set the new configuration in NPM config. Require JFrog Artifactory authetication.
$ npx artifactory-registry add
Check the new NPM configuration:
$ cat ~/.npmrc
remove
If you want to remove a NPM configuration:
$ npx artifactory-registry remove
This only remove the same data setted in artifactory.json
file.
FAQs
This only remove the same data setted in `artifactory.json` file.
We found that artifactory-registry demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.