Security News
Input Validation Vulnerabilities Dominate MITRE's 2024 CWE Top 25 List
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
landscape-node
Advanced tools
Landscape-Deploy contains a Node.js shell script for executing Landscape scripts and retrieving their results.
The deploy script requires the following docker image for sending commands to the Landscape API.
The above docker container requires the following environment variables to be defined:
export LANDSCAPE_API_URI
export LANDSCAPE_API_KEY
export LANDSCAPE_API_SECRET
If you are calling the deploy script with the --dev flag, the following environment variables must be defined (instead of or in addition to those listed above):
export LANDSCAPE_API_DEV_URI
export LANDSCAPE_API_DEV_KEY
export LANDSCAPE_API_DEV_SECRET
export LANDSCAPE_API_DEV_CERT_FOLDER
export LANDSCAPE_API_DEV_CERT_FILE
Run the following command for details on how execute the deploy script:
landscape-deploy --help
If you would like to see the logs in a human-readable format, install bunyan and deploy script as shown below:
npm install -g bunyan
landscape-deploy --script <id> --tag <name> [--dev] | bunyan
See https://github.com/trentm/node-bunyan for more information.
FAQs
A command-line tool for executing Landscape scripts.
We found that landscape-node demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.
Research
Security News
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.