Security News
Maven Central Adds Sigstore Signature Validation
Maven Central now validates Sigstore signatures, making it easier for developers to verify the provenance of Java packages.
configure-jfrog
Advanced tools
configure-jfrog
🐸The command-line utility configure-jfrog
is used to configure an NPM repository for using a JFrog SaaS Artifactory registry.
No installation is necessary when using npx
, although you may globally install with npm install --global configure-jfrog
. This is only recommended if you do not desire the latest version of the utility on each run.
Run the CLI command configure-jfrog
with optional flags and answer any prompts that may appear.
configure-jfrog [--directory -d] [--server-name -n] [--artifactory-key -k] [--registry -r] [--scope -s]
⚠️ WARNING: configure-jfrog will replace any existing .npmrc file at the specified directory.
name | alias | description |
---|---|---|
directory | -d | The relative or absolute path to the directory in which to configure NPM. This should be the root directory where your package.json lives. |
server-name | -n | The JFrog Artifactory server name: https://__<server-name>__.jfrog.io |
artifactory-key | -k | Your Artifactory API key. You must generate one for your user profile. |
registry | -r | The name of the registry on Artifactory you would like to use. |
scope | -s | The NPM @scope that your private packages are published to. It is best practice to always publish private packages under a scope so that there are no conflicts with public packages of the same name. |
npx configure-jfrog -d ~/Sites/example-package -n doximity -k $ARTIFACTORY_API_KEY -r npm-doximity -s dox
It may be helpful to create an NPM script to automatically configure your repository for new users:
{
"scripts": {
"configure-npm":
"npx configure-jfrog -d . -n doximity -k $ARTIFACTORY_API_KEY -r npm-doximity -s dox"
}
}
This will allow a new user to set up the private registry using their credentials.
FAQs
Configure JFrog Artifactory for an NPM package.
The npm package configure-jfrog receives a total of 0 weekly downloads. As such, configure-jfrog popularity was classified as not popular.
We found that configure-jfrog demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Maven Central now validates Sigstore signatures, making it easier for developers to verify the provenance of Java packages.
Security News
CISOs are racing to adopt AI for cybersecurity, but hurdles in budgets and governance may leave some falling behind in the fight against cyber threats.
Research
Security News
Socket researchers uncovered a backdoored typosquat of BoltDB in the Go ecosystem, exploiting Go Module Proxy caching to persist undetected for years.