data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
The Skillfarm Tracker Module for Alliance Auth tracks skill queues, sends notifications if skills finished and highlights them, making skill management easier for Skillfarms.
[!NOTE] AA Skillfarm needs at least Alliance Auth v4.6.0 Please make sure to update your Alliance Auth before you install this APP
Make sure you're in your virtual environment (venv) of your Alliance Auth then install the pakage.
pip install aa-skillfarm
Configure your Alliance Auth settings (local.py
) as follows:
'skillfarm',
to INSTALLED_APPS
To set up the Scheduled Tasks add following code to your local.py
CELERYBEAT_SCHEDULE["skillfarm_update_all_skillfarm"] = {
"task": "skillfarm.tasks.update_all_skillfarm",
"schedule": crontab(minute=0, hour="*/1"),
}
CELERYBEAT_SCHEDULE["skillfarm_check_skillfarm_notifications"] = {
"task": "skillfarm.tasks.check_skillfarm_notifications",
"schedule": crontab(minute=0, hour="*/12"),
}
python manage.py collectstatic
python manage.py migrate
With the Following IDs you can set up the permissions for the Skillfarm
ID | Description | |
---|---|---|
basic_access | Can access the Skillfarm module | All Members with the Permission can access the Skillfarm. |
corp_access | Has access to all characters in the corporation. | Can see all Skillfarm Characters from own Corporation. |
admin_access | Has access to all characters | Can see all Skillfarm Characters. |
The Following Settings can be setting up in the local.py
Setting Name | Descriptioon | Default |
---|---|---|
SKILLFARM_APP_NAME | Set the name of the APP | "Skillfarm" |
SKILLFARM_LOGGER_USE | Set to use own Logger File True/False | False |
SKILLFARM_STALE_STATUS | Set the Stale Status for Skillfarm Character in hours | 3 |
SKILLFARM_NOTIFICATION_COOLDOWN | Number of days to wait before resending a notification | 3 |
If you set up SKILLFARM_LOGGER_USE to True
you need to add the following code below:
LOGGING_SKILLFARM = {
"handlers": {
"skillfarm_file": {
"level": "INFO",
"class": "logging.handlers.RotatingFileHandler",
"filename": os.path.join(BASE_DIR, "log/skillfarm.log"),
"formatter": "verbose",
"maxBytes": 1024 * 1024 * 5,
"backupCount": 5,
},
},
"loggers": {
"skillfarm": {
"handlers": ["skillfarm_file", "console"],
"level": "INFO",
},
},
}
LOGGING["handlers"].update(LOGGING_SKILLFARM["handlers"])
LOGGING["loggers"].update(LOGGING_SKILLFARM["loggers"])
[!NOTE] Contributing You want to improve the project? Just Make a Pull Request with the Guidelines. We Using pre-commit
FAQs
A Skillfarm Tracker Module for Alliance Auth
We found that aa-skillfarm demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.