data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Application for retrieving prices of crypto currencies and notifying via Telegram.
Fetches...
Notifies users of price going up or down in increments via...
Prerequisites:
An easy way to setup Node is to use nvm
. Then run nvm use
to get the proper version specified in the project.
Then install the dependencies...
$ npm ci
Configuration:
Create a .env file with values needed in your setup.
logLevel=info|debug
currencies=[{"ticker": "bitcoin","increment": 1000}]
telegramApiKey=secret-key-for-bot
telegramChatIds=some-id,some-other-id
Useful commands:
$ npm run dev
- This will build images, scripts and styles and also watch changes in the two latter.
Tests are written in a BDD/Cucumber type syntax using mocha-cakes-2
. Try to write tests in a meaningful way as to
describe what it is you're testing and what resources are available. Testing does not only test a piece of code that it
actually works but is also used for documentation purposes. Focus on testing what is vital for the feature.
To run all tests (including linting)...
$ npm test
FAQs
Application for retrieving prices of crypto currencies and notifying via Telegram.
The npm package cryptifier receives a total of 0 weekly downloads. As such, cryptifier popularity was classified as not popular.
We found that cryptifier demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.