data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
luna-scanner
Advanced tools
LUNA is a software development tool for node.js (and other javascript) projects, with a focus on libraries. The goal of LUNA is to aid developers in better understanding how libraries are being utilized in their projects.
Inside any node.js project, run:
npx luna-scanner
After analyzing the source code, it will generate a LUNA report, which includes a visualization about the interaction between source code and libraries.
Via package.json
(defaults):
{
...
"luna": {
"debug": false, // toggle debug mode
"components": { // toggle components of LUNA
"callGraph": true, // detection of function calls within files
"dependencyTree": true, // detection of dependency chains
"libraryAPI": true, // detection of used API of libraries
},
"ignore": [], // array of glob patterns for LUNA's scanner to ignore
},
...
}
Via command line arguments (limited):
npx luna-scanner [path_to_project] [debug]
Much appreciated! I encourage you to use my feedback form.
FAQs
LUNA: Library Usage in Node.js Analyzer
The npm package luna-scanner receives a total of 0 weekly downloads. As such, luna-scanner popularity was classified as not popular.
We found that luna-scanner demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.