
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
CLI tool for developing VTEX apps.
First, install node and npm (Linux, Mac and Windows).
Then install VTEX Toolbelt globally:
npm install -g vtex
Add to your layout the script:
<script src="http://localhost:35729/livereload.js?snipver=1"></script>
To develop an app locally, open the directory where your VTEX app is then type:
vtex watch <sandbox-name>
You are free to set any name you want in the sandbox-name
parameter.
VTEX Toolbelt will upload all your app files to the sandbox specified and will be watching for any changes you make to them.
For this to work make sure this requirements are filled:
meta.json
(read more)meta.json
filevtex_sandbox
cookie (read more)To publish your VTEX app to VTEX Gallery, just type vtex publish
. The app will be published under the vendor name.
FAQs
The platform for e-commerce apps
The npm package vtex receives a total of 1,405 weekly downloads. As such, vtex popularity was classified as popular.
We found that vtex demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.