
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
To use this app, you need to install Python (version 3.10 or higher).
In a terminal window in a new directory, run pip install aamp_app
or pip install --upgrade aamp_app
to install the app. Use the latter one to upgrade the app after it's installed. All dependencies will be installed with it. You may wish to use a virtual python environment if you don't want this app or its dependencies to interfere with your current system. On Mac or Linux-based systems, do this by running the following commands before installing:
pip install virtualenv
: This line installs the virtualenv package which allows you to create virtual python environments.
virtualenv venv
: This line creates a virtual environment (called venv
) in the current directory. This will create a new folder (called venv
) with the environment data.
source venv/bin/activate
: This line activates the virtual environment. After activating the virtual environment, you should be able to see (venv)
in your terminal window. If you close the terminal window/tab, you will have to execute this command to activate the environment again before using the app.
To start the app, run aamp_app
. Enter the database user credentials for MongoDB. These credentials will be saved as plain text in a text file (called pw.txt
) in the same directory. Therefore, this app should only be used on trusted computers. If the connection to the database cannot be established using the provided credentials, you will be required to run aamp_app
again to retry. To delete the user credentials, simply delete the pw.txt
file.
Most devices should be able to connect to the app without any problems. However, certain devices require some drivers/software to create a connection. Due to the nature of the specific drivers/software, they must be installed separately.
Package app:
python3 setup.py sdist bdist_wheel
Upload to pip:
twine upload --skip-existing dist/*
FAQs
AAMP App
We found that aamp-app demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.