data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
gimbal-react
Advanced tools
Installation | Contributing | Code of Conduct | Twitter
A plugin that creates a React app to consume Gimbal's report.
npm install --save-dev gimbal-react
In your project's Gimbal configuration file, specify this plugin:
plugins:
- gimbal-react
{
"plugins": ["gimbal-react"]
}
module.exports = {
plugins: ['gimbal-react'],
};
This plugin has a few configs that you can modify:
build
Defaults to true
to build the generated React application. This will run npm run build
, if you'd like to specify a different command, instead of true
, pass a string of the command: yarn build
.clean
Defaults to true
, set to false
if you do not want to remove the out
directory prior to generating the React application.install
Defaults to true
to install the node dependencies in the generated React application. This will run npm install
, if you'd like to specify a different command, instead of true
, pass a string of the command: yarn
.logError
Default to false
, set to true
to show the error logs during commands like the build
and install
commands.out
Defaults to './artifacts/report'
which is relative to where Gimbal is running (or told to run).To specify a configuration, instead of the usage above, return an object:
plugins:
- plugin: gimbal-react
build: yarn build
install: yarn
{
"plugins": [
{
"plugin": "gimbal-react",
"build": "yarn build",
"install": "yarn"
}
]
}
module.exports = {
plugins: [
{
plugin: 'gimbal-react',
build: 'yarn build',
install: 'yarn',
},
],
};
Due to how npm and yarn install node dependencies, if it detects a dependency being installed is available in a parent directory, it won't install in the generated React application directory. This means you may need to change the out
to be somewhere that will install all the dependencies.
This project is MIT licensed.
FAQs
Create a React application to show the output from @modus/gimbal
The npm package gimbal-react receives a total of 1 weekly downloads. As such, gimbal-react popularity was classified as not popular.
We found that gimbal-react demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.