Security News
New Python Packaging Proposal Aims to Solve Phantom Dependency Problem with SBOMs
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.
juttle-viewer
Advanced tools
juttle-viewer is a development and presentation application for juttle programs that packages juttle-client-library, juttle-viz, and application logic to select and run juttle programs using a remote juttle-service.
In a production setting juttle-viewer can be run multiple ways.
Primarily, juttle-viewer is seen in juttle-engine where it is packaged along with juttle-service.
Additionally juttle-viewer can be run by itself. It will need an instance of juttle-service to play along with. It can be run standalone, but it also exports an express router and can be included in an express app.
npm install juttle-viewer
npm run juttle-viewer
The juttle-viewer command script has several options (such as changing the
juttle-service host), that can be viewed by running npm run juttle-viewer -h
Include juttle-viewer into an express app by doing this:
var express = require('express');
var viewer = require('juttle-viewer');
var app = express();
app.use(viewer({
juttleServiceHost: JUTTLE_SERVICE_HOST
}));
Once you've cloned the repo and have run npm install
, run this:
./bin/juttle-viewer -d
Note the -d
(or --dev
) argument is important because it uses
webpackMiddleware to serve and continually recompile your changes.
FAQs
application to develop and execute juttle programs
The npm package juttle-viewer receives a total of 2 weekly downloads. As such, juttle-viewer popularity was classified as not popular.
We found that juttle-viewer demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.
Security News
Socket CEO Feross Aboukhadijeh discusses open source security challenges, including zero-day attacks and supply chain risks, on the Cyber Security Council podcast.
Security News
Research
Socket researchers uncover how threat actors weaponize Out-of-Band Application Security Testing (OAST) techniques across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.