
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
violation-reporter
Advanced tools
Run complexity-report against javascript source code from grunt build.
grunt.loadNpmTasks('grunt-complexity-report');
grunt.initConfig({
complexity : {
js: {
files : [{ cwd: '.', src: ['/**/*.js'], expand : true}],
exclude: [],
options: {
pmdXML: '/pmd.xml',
teamcity: true //send buildStatisticValue to TeamCity
}
}
};
});
This project is based on the excellent grunt-complexity from vigetlabs. Unfortunately there are some bugs/missing features that stopped me from using it and the project seems to have been abandoned.
This uses the same concepts, but adds the ability to break on different levels of severity, making it more useful as a reporting tool. It also treats maintainability as a similar error to complexity, enabling it to fit within a single report style.
It currently only outputs to console and PMD format, but would be easy to extend to other XML formats.
npm install grunt-complexity-report
Stuart Campbell (campbes)
Released under the MIT License
FAQs
Genrate violation reports in various formats
We found that violation-reporter demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.