
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
node-peruse
Advanced tools
CLI tool designed to help Node.js developers analyze and review node.js project.
There are many more features to come, so keep on eye on this repository.
npm install -g node-peruse
yarn add -g node-peruse
Once installed, you can use node-peruse directly in your terminal.
node-peruse <command> [options]
Use the --dependencies
option to analyze and list all dependencies in your project.
node-peruse --dependencies
To check outdated packages in your project, use the --outdated
flag.
node-peruse --outdated
To check node.js version, use the --node-check
flag.
node-peruse --node-check
To check system memory is sufficient, use the --memory-check
flag.
node-peruse --memory-check
To run Node-Peruse without installing it globally, users can simply use:
npx node-peruse <command> [options]
mean you can remove node-peruse
with npx
and run the command directly and it will work the same way.
See CONTRIBUTING.md for more information on how to contribute to node-peruse.
FAQs
A powerful CLI tool designed to analyze your node.js application.
The npm package node-peruse receives a total of 1 weekly downloads. As such, node-peruse popularity was classified as not popular.
We found that node-peruse demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.