data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
dotenv-encode
Advanced tools
$ npm install dotenv-encode
Dotenv-encode is a package for encrypting or decrypting a file or folder using a password.
crypto
package for encrypting a file or folder with a key.$ npm dotenv-encode ./env/test.env -o ./encrypted/test.env -s MySecretKey
## Without secret/s, a prompt will ask for the secret
$ npm dotenv-encode ./env/test.env -o ./encrypted/test.env
This command will encrypt the content of the file ./env/test.env
in the file ./encrypted/test.env
with MySecretKey
as password.
You can also encrypt all the file in a folder :
$ npm dotenv-encode ./env -o ./env_encrypted -s MySecretKey
$ npm dotenv-encode ./env/test.env -o ./encrypted/test.env -s MySecretKey -d
This command will decrypt the content of the file ./env/test.env
in the file ./encrypted/test.env
with MySecretKey
as password.
$ dotenv-encode <path-input-file> --options <VALUE>
Options | Short | Mandatory | Description |
---|---|---|---|
--out | -o | yes | The path of the result file or folder (it will be created if does not exist) |
--secret | -s | no | Specify the password which would be used to encrypt or decrypt the file. |
--decrypt | -d | no | If present, the command will decrypt the input file |
In case the secret
is specified, a prompt will ask for the secret.
The decrypt
option does not take any parameters.
The path-input-file
is the file on which we will get the data from.
The main purpose of this repository is to continue evolving dotenv-encode, making it faster and easier to use. Development of this package happens in the open on GitHub, and I am grateful to anyone contributing bugfixes and improvements. Read below to learn how you can take part in improving Dotenv-encode.
I am monitoring for pull requests. I will review any pull request and either merge it, request changes to it, or close it with an explanation.
Before submitting a pull request, please make sure the following is done:
Dotenv-encode is MIT licensed.
FAQs
Unknown package
We found that dotenv-encode demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.