
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Upload a storefront cartridge to a Demandware WebDAV server from command line.
:; npm install -g dwupload
Instead of installing this as a global npm package, you can install it locally and access it as ./node_modules/.bin/dwupload
.
# uploading a carridge
:; dwupload --hostname example.demandware.net --username admin --password password --cartridge app_storefront_core --code-version version1
# uploading file(s) using configuration in `dw.json`
:; dwupload --file path/to/app.js --file path/to/style.css
# watch for file changes and upload automatically
:; dwupload watch --cartridge app_storefront_controllers
# delete a file, with root option
:; dwupload delete --file rootDir/path/to/file --root rootDir
# 2-factor authentication
:; dwupload --hostname cert.example.demandware.net --username admin --password password --p12 admin.p12 --passphrase passphrase
# get version information
:; dwupload version
See --help
for more information.
Exclude patterns can be declared via the -x
or --exclude
flag. This work for both file and folder exclude patterns. For example:
*.swp
**/node_modules/**
Please note that the **
after the folder name is important. Without it, child directories of node_modules
would still be included.
Instead of passing command line options every single time, you can store your config options in a dw.json
file in the current working directory instead. For example:
{
"hostname": "example.demandware.net",
"username": "user",
"password": "password",
"cartridge": ["cartridgeA", "cartridgeB"],
"code-version": "version2",
"p12": "path/to/file.p12",
"passphrase": "passphrase"
}
Command line options will always override the options delcared in the config file.
FAQs
Upload storefront cartridges to Salesforce B2C Commerce WebDAV server
We found that dwupload demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.