
Security News
OWASP 2025 Top 10 Adds Software Supply Chain Failures, Ranked Top Community Concern
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.
Introduces using blockware through blockctl commands.
The purpose of blockctl is to make it simple to automate things
either locally or on servers -
as well as giving people comfortable with terminals a way to quickly perform
certain actions.
npm i @blockware/blockctl -g
blockctl help
The tool itself is built up of a series of "commands". Each command is its own module except for a few built-in core commands.
It uses the NPM registry to install and update commands - and to install a new command you can simply do
blockctl install you-npm-command-module
or the short version
blockctl i you-npm-command-module
Upgrading is similar - simply write:
blockctl upgrade you-npm-command-module
To implement a command for blockctl we use @blockware/blockctl-command and the module must then be published as an NPM module for blockctl to install it
blockctl expects a command property in the package.json file
of the command. This command property should contain the name of your command -
e.g.
{
"name": "@blockware/blockctl-command-codegen",
"command": "codegen",
...
}
Typically you'd want to not publish and download all the time during development. for that purpose you can navigate to the folder in which you are developing a command and run
blockctl link [command-name]
The optional "command-name" parameter is to override what is in the
package.json file as mentioned before - or if nothing is there to
specify one.
blockctl will then create a symlink - very similar to
how npm link works - which allows it to find your local version of
the command.
FAQs
Blockware Command Line Utility
The npm package blockctl receives a total of 8 weekly downloads. As such, blockctl popularity was classified as not popular.
We found that blockctl demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.