
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
A chrome extension to easily manipulate chrome pages from the comfort of your text editor or OS.
npm i kino -g
and run kino init
to create the native messaging hostkino action
directlyBy default, there are actions defined for toggling video playback on youtube.com and egghead.io as an example. You can add other domains and define custom actions for them via the options page. Once this is done, you can trigger an action using the client to play the code for that action on an active chrome tab for the corresponding domain.
Here's a quick start video to help you get up and running:
There's currently not a great way to troubleshoot Kino issues without installing the extension unpacked. There are a few things you can do without going into Dev mode:
kino
globally and run kino init
?node
available at /usr/local/bin/node
? If not, ln -s <path to node> /usr/local/bin/node
and disable/enable the extension
/usr/bin/env node
when launching the native extension hosttools > extensions
allowed_origins
array in host/com.nicktomlin.kino.json
./bin/kino init
to install the native messaging hostThere is very light logging available via the background page:
kino action toggle
and see if there is any loggingFAQs
Remote
The npm package kino receives a total of 1 weekly downloads. As such, kino popularity was classified as not popular.
We found that kino demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.