
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Hobknob is a feature toggle front-end built on top of etcd. It allows users to create, maintain and toggle feature toggles and keeps an audit of all changes.
The benefit of using etcd as a data store is that there is no need to write an additional API to query for toggles, or a eventing system to update consumers, as it is baked into etcd. Etcd has its own implementation using long polling.
###Screenshots
#####The Dashboard
#####Creating Toggle
#####Audit View
###Running the app locally The quickest way to run the app locally is to use Vagrant. If you don't have Vagrant you should install it from here.
#####Running using Vagrant
vagrant-up
will spin up a vagrant instance and install etcd and the app in a Docker container with the application running on port 3006
#####Running manually The application is written against NodeJS version 0.10.26. This should be installed prior to trying to run the application. After checkout you should install dependencies using npm.
Hobknob relies on you having a local install of etcd. To get it running look at the docs it's incredibly easy to get running. Make sure you start it up with the -cors flag:
$ ./bin/etcd -cors http://127.0.0.1:3006
# Clone the app
$ git clone git@github.com:opentable/hobknob.git
$ cd hobknob
# Install npm
$ sudo npm install -y
# Install bower dependencies
$ npm install -g bower
$ bower install
# Prepare config (this is a temporary measure)
$ grunt
# Run the app
$ node server/dev-app.js
You can then access the site on http://127.0.0.1:3006
###Testing with Protractor We've integrated protractor for end-to-end testing. To start these tests run:
# Make sure you have the app running first
$ grunt test
FAQs
Front end for managing feature toggles in etcd
The npm package hobknob receives a total of 1 weekly downloads. As such, hobknob popularity was classified as not popular.
We found that hobknob demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.