Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
code-push
Advanced tools
The code-push npm package is a service that enables React Native and Cordova developers to deploy mobile app updates directly to their users' devices. This allows for instant updates without requiring users to go through the app store update process.
Release Updates
This feature allows developers to release updates to their apps. The `release` method takes parameters such as the app name, deployment name, update contents, target binary version, description, whether the update is mandatory, and the rollout percentage.
const codePush = require('code-push');
codePush.release(appName, deploymentName, updateContents, targetBinaryVersion, description, isMandatory, rolloutPercentage);
Check for Updates
This feature allows the app to check if there are any updates available. The `checkForUpdate` method takes a deployment key and returns a promise that resolves with the update information if an update is available.
const codePush = require('code-push');
codePush.checkForUpdate(deploymentKey).then((update) => {
if (!update) {
console.log('The app is up to date.');
} else {
console.log('An update is available: ' + update.description);
}
});
Rollback Updates
This feature allows developers to rollback to a previous version of the app. The `rollback` method takes parameters such as the app name, deployment name, and target binary version.
const codePush = require('code-push');
codePush.rollback(appName, deploymentName, targetBinaryVersion);
Expo Updates is a service that allows developers to deploy updates to their React Native apps built with Expo. It provides similar functionality to CodePush, such as over-the-air updates, but is specifically designed for apps built with the Expo framework.
App Center is a comprehensive app lifecycle management service by Microsoft that includes features for build, test, distribute, and monitor. It includes CodePush as part of its distribution service, providing similar over-the-air update capabilities along with additional features for continuous integration and delivery.
React Native Update is a library that provides over-the-air updates for React Native apps. It offers similar functionality to CodePush, allowing developers to push updates directly to users without going through the app store. However, it is less feature-rich compared to CodePush and App Center.
CodePush is a cloud service that enables Cordova and React Native developers to deploy mobile app updates directly to their users' devices. It works by acting as a central repository that developers can publish updates to (JS, HTML, CSS and images), and that apps can query for updates from (using provided client SDK for Cordova and React Native). This allows you to have a more deterministic and direct engagement model with your userbase, when addressing bugs and/or adding small features that don't require you to re-build a binary and re-distribute it through the respective app stores.
To get started using CodePush, refer to our documentation, otherwise, read the following steps if you'd like to build/contribute to the project from source.
NOTE: If you need information about code-push management CLI, you can find it in v3.0.1.
git clone https://github.com/Microsoft/code-push.git
npm run setup
to install the NPM dependencies of management SDK.npm run build
to build the management SDK for testing.npm run build:release
to build the release version of management SDK.npm run test
from the root of the project..vscode/launch.json
file.camelCase
for local variables and imported modules, PascalCase
for types, and dash-case
for file namesThis project has adopted the Microsoft Open Source Code of Conduct. For more information see the Code of Conduct FAQ or contact opencode@microsoft.com with any additional questions or comments.
A JavaScript library for programmatically managing your CodePush account (e.g. creating apps, promoting releases), which allows authoring Node.js-based build and/or deployment scripts, without needing to shell out to the App Center CLI.
Create a token to authenticate with the CodePush server using the following App Center CLI command:
appcenter tokens create -d "DESCRIPTION_OF_THE_TOKEN"
Please copy your API Token
and keep it secret. You won't be able to see it again.
Install the management SDK by running npm install code-push --save
Import it using one of the following statement: (using ES6 syntax as applicable):
const CodePush = require("code-push");
import CodePush from "code-push";
Create an instance of the CodePush
class, passing it the API Token
you created or retrieved in step #1:
const codePush = new CodePush("YOUR_API_TOKEN");
Begin automating the management of your account! For more details on what you can do with this codePush
object, refer to the API reference section below.
The code-push
module exports a single class (typically referred to as CodePush
), which represents a proxy to the CodePush account management REST API. This class has a single constructor for authenticating with the CodePush service, and a collection of instance methods that correspond to the commands in the App Center CLI, which allow you to programmatically control every aspect of your CodePush account.
Note: access key
here refers to an AppCenter API Token.
addAccessKey(description: string): Promise<AccessKey> - Creates a new access key with the specified description (e.g. "VSTS CI").
addApp(name: string, os: string, platform: string, manuallyProvisionDeployments: boolean = false): Promise<App> - Creates a new CodePush app with the specified name, os, and platform. If the default deployments of "Staging" and "Production" are not desired, pass a value of true for the manuallyProvisionDeployments parameter.
addCollaborator(appName: string, email: string): Promise<void> - Adds the specified CodePush user as a collaborator to the specified CodePush app.
addDeployment(appName: string, deploymentName: string): Promise<Deployment> - Creates a new deployment with the specified name, and associated with the specified app.
clearDeploymentHistory(appName: string, deploymentName: string): Promise<void> - Clears the release history associated with the specified app deployment.
getAccessKey(accessKey: string): Promise<AccessKey> - Retrieves the metadata about the specific access key.
getAccessKeys(): Promise<AccessKey[]> - Retrieves the list of access keys associated with your CodePush account.
getApp(appName: string): Promise<App> - Retrieves the metadata about the specified app.
getApps(): Promise<App[]> - Retrieves the list of apps associated with your CodePush account.
getCollaborators(appName: string): Promise<CollaboratorMap> - Retrieves the list of collaborators associated with the specified app.
getDeployment(appName: string, deploymentName: string): Promise<Deployment> - Retrieves the metadata for the specified app deployment.
getDeploymentHistory(appName: string, deploymentName: string): Promise<Package[]> - Retrieves the list of releases that have been made to the specified app deployment.
getDeploymentMetrics(appName: string, deploymentName: string): Promise<DeploymentMetrics> - Retrieves the installation metrics for the specified app deployment.
getDeployments(appName: string): Promise<Deployment[]> - Retrieves the list of deployments associated with the specified app.
patchRelease(appName: string, deploymentName: string, label: string, updateMetadata: PackageInfo): Promise<void> - Updates the specified release's metadata with the given information.
promote(appName: string, sourceDeploymentName: string, destinationDeploymentName: string, updateMetadata: PackageInfo): Promise<Package> - Promotes the latest release from one deployment to another for the specified app and updates the release with the given metadata.
release(appName: string, deploymentName: string, updateContentsPath: string, targetBinaryVersion: string, updateMetadata: PackageInfo): Promise<Package> - Releases a new update to the specified deployment with the given metadata.
removeAccessKey(accessKey: string): Promise<void> - Removes the specified access key from your CodePush account.
removeApp(appName: string): Promise<void> - Deletes the specified CodePush app from your account.
removeCollaborator(appName: string, email: string): Promise<void> - Removes the specified account as a collaborator from the specified app.
removeDeployment(appName: string, deploymentName: string): Promise<void> - Removes the specified deployment from the specified app.
renameApp(oldAppName: string, newAppName: string): Promise<void> - Renames an existing app.
renameDeployment(appName: string, oldDeploymentName: string, newDeploymentName: string): Promise<void> - Renames an existing deployment within the specified app.
rollback(appName: string, deploymentName: string, targetRelease?: string): Promise<void> - Rolls back the latest release within the specified deployment. Optionally allows you to target a specific release in the deployment's history, as opposed to rolling to the previous release.
transferApp(appName: string, email: string): Promise<void> - Transfers the ownership of the specified app to the specified account.
When an error occurs in any of the methods, the promise will be rejected with a CodePushError object with the following properties:
FAQs
Management SDK for the CodePush service
The npm package code-push receives a total of 106,940 weekly downloads. As such, code-push popularity was classified as popular.
We found that code-push demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.