
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
snyk-to-html
Advanced tools
The Snyk JSON to HTML Mapper takes the json outputted from snyk test --json
and creates a local HTML file displaying the vulnerabilities discovered.
First, Install the Snyk JSON to HTML Mapper using npm:
npm install snyk-to-html -g
Alternatively, you can skip this step, clone the repo and run the script locally (using node ./snyk-to-html.js
)
Change directory to your package's root folder, then use of the two ways below to generate the HTML report.
Directly streaming the results to snyk-to-html:
Run the following line to create a file called results.html
:
snyk test --json | snyk-to-html -o results.html
Using a temporary file:
Generate JSON data by running snyk test
and save the output to a file
snyk test --json > results.json
Pass the resulting JSON file to Snyk's JSON to HTML Mapper
snyk-to-html -i results.json -o results.html
Simply open your new file (results.html
above) in a browser, and rejoice.
FAQs
Convert JSON output from `snyk test --json` into a static HTML report
The npm package snyk-to-html receives a total of 95,822 weekly downloads. As such, snyk-to-html popularity was classified as popular.
We found that snyk-to-html demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.