
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
binary-distributor
Advanced tools
binary-distributor is an npm package that simplifies the distribution of platform-specific binary applications via npm. It allows you to include and install pre-built binaries based on the user's system and architecture along with your JavaScript module.
Initialize minimal npm package:
npm init -y
Pay attentions fields name
and version
should be defined and same as in your binary package.
Install binary-distributor:
npm install binary-distributor --save-dev
Add postinstall
and preuninstall
scripts to your package.json
:
{
"scripts": {
"postinstall": "binary-distributor install",
"preuninstall": "binary-distributor uninstall"
}
}
Add binary-distributor
section to your package.json
:
{
"binary-distributor": {
"url-template": "url/to/your/binary.tar.gz"
}
}
Following variables are available to customize the URL template:
{name}
- Name of the package read from package.json file.{version}
- Version number read from package.json file.{platform}
- Name of the operating system (Read more).{arch}
- The operating system CPU architecture (Read more).Create launch script launch.js
with following content:
#!/usr/bin/env node
require('binary-distributor')
.launch(__dirname);
Add bin
section to your package.json
:
{
"bin": "./launch.js"
}
Then you can publish your package to npm registry:
npm publish
FAQs
Lightweight library to distribute binaries via npm
The npm package binary-distributor receives a total of 0 weekly downloads. As such, binary-distributor popularity was classified as not popular.
We found that binary-distributor demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.