
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
This is a CLI for securenv API where you can upload your env files to a vault and share you your team from a secure way.
You must be authenticated to get or set any data to secure vault.
$ npx securenv login [username] [password] [api-host]
The session will be available for 1h and after the first login you can use an shortcut to login withou pass the api-host.
$ npx securenv login [username] [password]
To GET, SET or LIST any information from the vault you have to be logged in and must have all the grants to to the job.
$ npx securenv set [project-name] [environment]
So if you want to upload your env.production file to the vault, you have to do:
$ npx securenv set my-project production
# this will upload .env.production to my-project production vault
By the way, if you dont say the environment, securenv will use .env file in production env.
$ npx securenv set my-project
# this will upload .env to my-project production vault
$ npx securenv get [project-name] [environment]
So if you want to download your env.production file from the vault, you have to do:
$ npx securenv get my-project production
# this will replace .env.production file with the content of the vault
$ npx securenv get my-project staging
# this will replace .env.staging file with the content of the vault
List all avaiable projects and environments that you have grants.
$ npx securenv list [project-name]
# this will list all available environments that you have grant
When you list list all avaiable projects and environments that you have grants, securenv will show to you up 10 old versions of some environment.
If you want to get an specific version you have to get the versionId you want and do:
$ npx securenv get [project-name] [environment] [version-id]
# this will list all available environments that you have grant
FAQs
Securenv its a CLI for securenv API that stores and gets secure env files
The npm package securenv receives a total of 8 weekly downloads. As such, securenv popularity was classified as not popular.
We found that securenv demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.