
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Inspect the caller.
You might simply install it with pip:
pip install backframe
If you use Poetry, then you might want to run:
poetry add backframe
[!Note] If you use Windows, it is highly recommended to complete the installation in the way presented below through WSL2.
Fork the backframe repository on GitHub.
Install Poetry.
Poetry is an amazing tool for managing dependencies & virtual environments, building packages and publishing them.
You might use pipx to install it globally (recommended):
pipx install poetry
If you encounter any problems, refer to the official documentation for the most up-to-date installation instructions.
Be sure to have Python 3.8 installed—if you use pyenv, simply run:
pyenv install 3.8
Clone your fork locally and install dependencies.
git clone https://github.com/your-username/backframe path/to/backframe
cd path/to/backframe
poetry env use $(cat .python-version)
poetry install
Next up, simply activate the virtual environment and install pre-commit hooks:
poetry shell
pre-commit install
For more information on how to contribute, check out CONTRIBUTING.md.
Always happy to accept contributions! ❤️
© Copyright by Bartosz Sławecki (@bswck).
This software is licensed under the terms of MIT License.
FAQs
Inspect the caller.
We found that backframe demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.