data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
A command-line tool for quickly creating new projects from templates. Automatically discovers and provides commands for all templates in the templates directory.
# Clone the repository
git clone https://github.com/whiteduck-dev/project-starter.git
cd project-starter
# Install using uv
uv build
uv pip install -e .
Install uv
Visit the official documentation for detailed installation instructions:
List available templates:
uvx whiteduck --help
Create a new project:
# Basic usage - creates in current directory
uvx whiteduck react
# Specify output directory
uvx whiteduck react -o my-project
Get help for a specific template:
uvx whiteduck react --help
react - A modern React project template with:
lib - A template for creating Python libraries
package - A template for Python packages
src/whiteduck/templates/
api
for whiteduck api
)For example:
# Create a new template
mkdir src/whiteduck/templates/api
# Add template files
cp -r my-api-files/* src/whiteduck/templates/api/
# The command is now available
uv run whiteduck api --help
Copyright © 2024 white duck GmbH. All rights reserved.
FAQs
Add your description here
We found that whiteduck demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.