
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
#BSSH (🐝SSH)
Bulk SSH is a CLI for executing remote commands via SSH on multiple servers.
Usage: bssh [options] "<command to execute remotely>"
Options | Description |
---|---|
-V, --version | output the version number |
-f, --file [filepath] | What file contains the SSH commands to run the command with? |
-i, --identity [identity_file] | The path to your keypair file |
-s, --synchronous | Just run everything and let results come back in live. More difficult to read results, but more efficient to run commands. |
-u, --user [username] | The username you wish to use |
-h, --help | output usage information |
In certain circumstances you just want to go directly to a specific docker instance (say to get to a shell within it)
Rather than:
ssh -i somekey.key ubuntu@swarmmaster.domain.com
sudo docker service ls
sudo docker service ps k28s53gd52fd
exit
ssh -i another.key ubutu@worker3.domain.com
sudo docker exec -it 781nd7s5g2s ash
Use BSSH
bssh -f ./production-server-list -i somecommon.key -u ubuntu "sudo docker ps"
ssh -i somecommon.key ubuntu@worker3.domain.com
sudo docker exec -it 781nd7s5g2s ash
If you have an SSH config set up it is even simpler as you can cut out the key and user:
bssh -f ./production-server-list "sudo docker ps"
ssh -i somecommon.key ubuntu@worker3.domain.com
sudo docker exec -it 781nd7s5g2s ash
FAQs
Execute commands on multiple remote servers using SSH
We found that bulk-ssh demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.