Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
pentest-report-generator
Advanced tools
Generate HTML and PDF penetration testing reports from markdown files.
Usage: genpenrep [OPTIONS]
Options:
-s, --sources DIRECTORY Directory with .md source files
-o, --output DIRECTORY Directory to write output files
-c, --compress Create .zip archive with the HTML source files
--only-pdf Do not output HTML files
--only-html Do not output PDF file
--help Show this message and exit.
You can see an example penetration test and the output in the example
directory.
# Why is pipx better than pip? https://pypa.github.io/pipx/#how-is-it-different-from-pip
pipx install pentest-report-generator
pip install pentest-report-generator
The software is also available as a Docker container.
docker run -it --rm -v "$PWD/sources:/data" -v "$PWD/output:/output" 'staticnoise/pentest-report-generator' -s /data -o /output
pipx install --editable ./
podman login docker.io
poetry build
# update Dockerfile and bump-up the version number if necessary
podman build -t docker.io/staticnoise/pentest-report-generator .
# test the created docker container
podman run -it --rm -v "$PWD/sources:/data:z" -v "$PWD/output:/output:z" 'docker.io/staticnoise/pentest-report-generator' -s /data -o /output
# publish the Docker image
podman push docker.io/staticnoise/pentest-report-generator
poetry config repositories.pypi https://upload.pypi.org/legacy/
# you will be prompted for password
poetry config http-basic.pypi staticnoise
poetry build
poetry publish --dry-run
poetry publish
Copyright (c) 2022-2023 Adam Chovanec
Permission is hereby granted, free of charge, to any person
obtaining a copy of this software and associated documentation
files (the "Software"), to deal in the Software without
restriction, including without limitation the rights to use,
copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the
Software is furnished to do so, subject to the following
conditions:
The above copyright notice and this permission notice shall be
included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES
OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR
OTHER DEALINGS IN THE SOFTWARE.
FAQs
Generate penetration testing report from markdown files
We found that pentest-report-generator demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.