
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
chromascope
Advanced tools
Visually compare the same URL or DOM element in different browsers, from the safety of the command line.
Chromascope is a tool for visualizing the diff of a given URL between chromium, webkit, and firefox. It uses Playwright to capture the screenshots and pixelmatch to compare them.
Can be installed globally with pnpm|npm|yarn:
pnpm add -g chromascope
npm i -g chromascope
yarn global add chromascope
or run it directly with npx:
npx chromascope <command> [options]
$ chromascope --help
chromascope/x.x.x
Usage:
$ chromascope <command> [options]
Commands:
diff <url> Diff the URL in chromium, firefox, and webkit. Using chromium as the base.
For more info, run any command with the `--help` flag:
$ chromascope diff --help
Options:
-h, --help Display this message
-v, --version Display version number
$ chromascope diff --help
chromascope/x.x.x
Usage:
$ chromascope diff <url>
Options:
-e, --element <selector> Diff only the element with the given selector
-f, --full-page Take a full page screenshot
-v, --verbose Show more output
-s, --save-diff Save generated diff as png
-t, --threshold <threshold> Set the threshold for the diff (default: 0.2)
-f, --folder <folder> Set the base folder for chromascope runs (default: chromascope-runs)
-h, --help Display this message
1.0.3
FAQs
Visually compare the same URL or DOM element in different browsers, from the safety of the command line.
The npm package chromascope receives a total of 2 weekly downloads. As such, chromascope popularity was classified as not popular.
We found that chromascope demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.