data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
#hg++ - power tools for mercurial
Do you keep multiple clones of your repository on your system and find keeping them merged and fresh a chore?
Then this is the tool for you.
Example gif of hgpp merge in action
hgpp --help
Show help.
hgpp
Default command - lists the current branch name for each configured repo.
hgpp pull
Does an hg pull
on each repo.
hgpp merge
First does an hg pull, and then attempts to merge. The project will be skipped if:
####Install the tool (globally):
npm install hgpp -g
####Make a .hgpp
config file in your home directory:
~/.hgpp
for unix
c:/users/foobar/.hgpp
for Windows
This config file is standard JSON:
{
"projects": [
{ "path": "C:\\code\\myproj" },
{ "path": "C:\\code\\myproj_clone1" },
{ "defaultBranch": "temporary-other-default", "path": "C:\\code\\myproj_clone2" }
],
"maxConcurrent": 3
}
Specify paths to your projects.
Optionally specify a different default
branch - this is useful when you're branching off of a parent branch and want to keep in sync with that parent rather than default
. If no value is provided, this defaults to default
.
maxConcurrent is optional, and specifies how many simultaneous mercurial actions it will try perform. Defaults to 3.
FAQs
hg++ power tools
We found that hgpp demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.