data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Organize package changes and releases.
npm i -D auri
yarn add -D auri
pnpm add -D auri
Run commands:
npx auri
pnpm exec auri
yarn auri
.auri
directoryconfig.json
inside .auri
repo
, user:email
AURI_GITHUB_TOKEN
in Github actions secretsauri.publish
script to each package's package.json - this will be the command Auri will use to publishrepository
Required Full Github repository url.
{
"repository": "https://github.com/pilcrowOnPaper/auri"
}
scripts
format
Command for formatting code. Will run after Auri updates your changelogs and package.json.
{
"scripts": {
"format": "pnpm format"
}
}
publish_setup
Command to run before any publish command runs.
{
"scripts": {
"publish_setup": "pnpm build-dependency"
}
}
auri add
Creates a new changeset in .auri
directory. A changeset is a markdown file:
---
package: "" # package name (package.json)
type: "" # "major", "minor", "patch" (semver)
---
<!-- changeset content -->
auri prepare
auri
branchauri
=> main
auri publish
Compares version of package.json and one in the NPM registry, and runs auri.publish
if it differs
FAQs
Organize package changes and releases
The npm package auri receives a total of 316 weekly downloads. As such, auri popularity was classified as not popular.
We found that auri demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.