
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
The Python package of Tenzir provides a flexible control plane to integrate Tenzir with other security tools.
Note The Python effort is still highly experimental and subject to rapid change. Please do not consider it for production use.
To get started, clone the Tenzir repository and install the Python package via Poetry:
git clone https://github.com/tenzir/tenzir.git
cd tenzir/python
poetry install -E module
We recommend that you work with an editable installation, which is the default
for poetry install
.
Run the unit tests via pytest:
poetry run pytest
Run the integrations tests via Docker Compose and pytest:
./docker-poetry-run.sh pytest -v
The following instructions concern maintainers who want to publish the Python package to PyPI.
Note Our releasing scripts and CI run these steps automatically. You do not need to intervene anywhere. The instructions below merely document the steps taken.
Prior to releasing a new version, bump the version, e.g.:
poetry version 2.3.1
This updates the pyproject.toml
file.
Add a Test PyPi repository:
poetry config repositories.test-pypi https://test.pypi.org/legacy/
Get the token from https://test.pypi.org/manage/account/token/.
Store the token:
poetry config pypi-token.test-pypi pypi-XXXXXXXX
Publish:
poetry publish --build -r test-pypi
Get the token from https://pypi.org/manage/account/token/.
Store the token:
poetry config pypi-token.pypi pypi-XXXXXXXX
Publish
poetry publish --build
FAQs
A security telemetry engine for detection and response
We found that tenzir demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.