data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Model-, taskmodule-, and metric-implementations as well as document processing utilities for PyTorch-IE.
Available models:
Available taskmodules:
Available metrics:
Document processing utilities:
pip install pie-modules
To install the latest version from GitHub:
pip install git+https://git@github.com/ArneBinder/pie-modules.git
git clone https://github.com/ArneBinder/pie-modules
cd pie-modules
poetry install
Finally, to run any of the below commands, you need to activate the virtual environment:
poetry shell
Note: You can also run commands in the virtual environment without activating it first: poetry run <command>
.
pre-commit run -a
run all tests with coverage:
pytest --cov --cov-report term-missing
git switch --create release main
poetry version <PATCH|MINOR|MAJOR>
,
e.g. poetry version patch
for a patch release. If the release contains new features, or breaking changes,
bump the minor version (this project has no main release yet). If the release contains only bugfixes, bump
the patch version. See Semantic Versioning for more information.git commit --message="release <NEW VERSION>" pyproject.toml
,
e.g. git commit --message="release 0.13.0" pyproject.toml
git push origin release
release
branch on GitHub.release
branch. This is important, because otherwise the next release will fail.FAQs
Model and Taskmodule implementations for PyTorch-IE
We found that pie-modules demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.