
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
In reference to Spacebrew by Rockwell Lab (http://www.rockwellgroup.com/search/LAB)
Spacebro automagically links apps between them. It binds them based on events
. It is here to help you connect your apps together.
You define a list of events, and make sure your client apps emits and listen to them.
It follow a centralized model where each apps automagically connects thru zeroconf and socket.io to the Spacebro server. Then each of them register a supplementary list of events.
Space bro use:
$ sudo apt-get install avahi-daemon avahi-discover libnss-mdns libavahi-compat-libdnssd-dev curl build-essential
$ npm i --save spacebro
You can install globally by using :
$ npm i -g --save spacebro
Spacebro is awaiting a config file that looks like :
{
"server": {
"port": 8888,
"serviceName": "spacebro"
},
"events": ["event-1", "event-2", "event-3"]
}
The port
define where Spacebro (socket.io) will listen.
The serviceName
is the name that Spacebro will use over Zeroconf.
The events
array allows you to define a list of events that you want
to register.
const config = require('../config.json')
var spacebro = require('spacebro')
spacebro.init(config)
You can use the bin
:
spacebro --port 8888
or
spacebro --port 8888 --servicename woowoo
By default the service name is spacebro
This is useful if you want to use the spacebro-client
You can test sending events with the dev/send-events.js
script. Run $ npm run send-events
.
Please follow standard style conventions.
FAQs
Spacebro is a socket.io server that provides an API to bind apps together!
The npm package spacebro receives a total of 2 weekly downloads. As such, spacebro popularity was classified as not popular.
We found that spacebro demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.