
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
simple-aznpmrcs
Advanced tools
Every 30/60/90 days the PAT was expired that was used for installing NPM dependencies.
Which meant I needed to login, create a new PAT, covert it to base64, update NPMRC and then I was able to proceed.
If you only have one Azure DevOps organization then it is not handy but doable.
I use multiple and therefor needed to login to each of the different Organizations and do the update circus.
And ofcourse, that was always when you can cannot really use it >.<
So in comes this module!
It can create NPMRC' based on the given aZOrganization
, azProject
and feedname
A PAT is generate automatically and you can update it with ease.
As this is automated, there is no need to have very long lived PAT's. You can use shortlived because well its easy to regenerate.
It uses the Azure CLI to connect.
You need to make sure that you have this installed, and are logged in (az login
)
After that you are good to go :-)
You can either install it globally npm install -g simple-aznpmrcs
or use npx npx simple-aznpmrcs
to execute the commands.
For creating a NPMRC a few parameters are required:
Note: azOrganization & azProject are optional if repository url is provided in your package.json
Example Azure DevOps url: https://dev.azure.com/henkvandenbrink/kitchensink
azOrganization = henkvandenbrink
azProject = kitchensink
feedName = As created.
Example:
npx simple-aznpmrcs create henkvandenbrink kitchensink npm-feed
When you have create one or more npmrcs you can easily switch:
npx simple-aznpmrcs example-npmrc
For updating you only need to provide the name of the NPMRC that was created earlier.
npx simple-aznpmrcs update example-npmrc
This module uses npmrc npm module to create and switch the npmrc.
FAQs
CLI to help with setting up feeds and authentication for Azure DevOps
The npm package simple-aznpmrcs receives a total of 0 weekly downloads. As such, simple-aznpmrcs popularity was classified as not popular.
We found that simple-aznpmrcs demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.