data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
A cli tool for tortoise-orm, build on top of click and ptpython.
You can just install from pypi.
pip install tortoise-cli
> tortoise-cli -h 23:59:38
Usage: tortoise-cli [OPTIONS] COMMAND [ARGS]...
Options:
-V, --version Show the version and exit.
-c, --config TEXT TortoiseORM config dictionary path, like
settings.TORTOISE_ORM
-h, --help Show this message and exit.
Commands:
shell Start an interactive shell.
First, you need make a TortoiseORM config object, assuming that in settings.py
.
TORTOISE_ORM = {
"connections": {
"default": "sqlite://:memory:",
},
"apps": {
"models": {"models": ["examples.models"], "default_connection": "default"},
},
}
Then you can start an interactive shell for TortoiseORM.
tortoise-cli -c settings.TORTOISE_ORM shell
Or you can set config by set environment variable.
export TORTOISE_ORM=settings.TORTOISE_ORM
Then just run:
tortoise-cli shell
This project is licensed under the Apache-2.0 License.
FAQs
A cli tool for tortoise-orm, build on top of click and ptpython.
We found that tortoise-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.