
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Alpha Hint: This is work in progress.
This small command line tool is a javascript powered cli wrapper for duplicity. It wraps the output of the python-based duplicity cli tool into javascript calls and returns json.
Since it's a npm module, it might be integrated into an existing nodejs application.
$ npm install duplicity -g
Let's say, you want to backup a folder called myproject into a local backup at file://backup.
Create a file called .duplicity.json for your configuration (the passphrase will be used for encryption!):
{
"env": {
"PASSPHRASE": "hans"
}
}
Backup myproject to the backup directory:
$ duplicity.js full-backup myproject file://backup
{ StartTime: Mon Dec 01 2014 15:46:34 GMT+0100 (CET),
EndTime: Mon Dec 01 2014 15:46:34 GMT+0100 (CET),
ElapsedTime: '0.01',
SourceFiles: '4',
SourceFileSize: '238',
NewFiles: '4',
NewFileSize: '238',
DeletedFiles: '0',
ChangedFiles: '0',
ChangedFileSize: '0',
ChangedDeltaSize: '0',
DeltaEntries: '4',
RawDeltaSize: '0',
TotalDestinationSizeChange: '254',
Errors: '0' }
Verify the backup:
$ duplicity.js verify myproject file://backup
{ newFiles: [ 'hans23', 'hans23/hasn23', 'test2.txt' ],
deletedFiles: [ 'test.txt' ],
modifiedFiles: [ '.' ],
otherDifferences: [] }
List all files in the backup:
$ duplicity.js files file://backup
[ { date: Mon Dec 01 2014 15:09:46 GMT+0100 (CET), file: '.' },
{ date: Mon Dec 01 2014 15:09:50 GMT+0100 (CET),
file: 'hans23' },
{ date: Mon Dec 01 2014 15:09:50 GMT+0100 (CET),
file: 'hans23/hasn23' },
{ date: Mon Dec 01 2014 14:59:53 GMT+0100 (CET),
file: 'test2.txt' } ]
Get the backup status of the backup:
$ duplicity.js status file://backup
[ { type: 'Full',
date: Mon Dec 01 2014 15:49:03 GMT+0100 (CET),
volumes: '1' },
{ type: 'Incremental',
date: Mon Dec 01 2014 15:49:05 GMT+0100 (CET),
volumes: '1' } ]
node-duplicity (duplicity.js) is copyright 2014 by DracoBlue and licensed under the terms of MIT License.
FAQs
Wrapper for the duplicity cli tool (with json output)
We found that duplicity demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.