Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
To install:
npm install -g burn-it
Usage:
usage: burn <command> <image_name> [command-args] [options]
Commands:
it <name>[@<version>] [components..] create a new image
ls <name>[@<version>] list all images by the name
rm <name>[@<version>] delete image(s)
run <name>[@<version>] launch instances using the image
Options:
-r, --region AWS region name [default: "us-west-2"]
-s, --subnet-id Subnet ID
-p, --vpc-id VPC ID
-e, --env-vars Environment variable key-value pairs separated by
command (example: "key1=val1,key2=val2")
-b, --base-image Base image name and optional version (e.g.
"my_base_image", "my_base_image@1.2.3")
-B, --base-image-id Base image AMI ID [default: "ami-bd58c98d"]
-d, --debug Debug mode [default: false]
-k, --key-pair Key pair name
-g, --security-groups List of security group IDs separated by comma
-t, --instance-type Instance type [default: "m1.small"]
-u, --user-data User data (BASE64 encoded)
-U, --user-data-file User data file (contents must NOT be BASE64 encoded)
-i, --iam-role IAM profile name
-x, --exclude-instances Whether to exclude the instances or not
[default: false]
-c, --instance-count The number of instances [default: 1]
-a, --access-key AWS access key
-A, --secret-key AWS secret key
Examples:
burn it my_app_image Create an image with name of "my_app_image" and
version of "1.0.0".
burn it my_app_image@2.3.4 Create an image with name of "my_app_image" and
version of "2.3.4".
burn run my_app_image 4 Create 4 instances using the image with name of
"my_app_image".
burn ls my_app_image List all images with name of "my_app_image" and
their instances.
burn ls my_app_image@1.x List all images with name of "my_app_image" and
version of "1.x" and their instances.
burn rm my_app_image@1.x Delete all images with name of "my_app_image"
and version of "1.x" and their instances.
FAQs
To install: ``` npm install -g burn-it ```
The npm package burn-it receives a total of 2 weekly downloads. As such, burn-it popularity was classified as not popular.
We found that burn-it demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.