data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
See the GitHub Repository
Ziya is a code assist tool for AWS Bedrock models. It can read your entire codebase and answer questions.
The current version only performs read operations. However, future versions will be able to:
The easiest way is to set the env variables with access to AWS Bedrock claude models.
export AWS_ACCESS_KEY_ID=<YOUR-KEY>
export AWS_SECRET_ACCESS_KEY=<YOUR-SECRET>
pip install ziya
ziya
Then navigate to http://localhost:6969 in your browser and start chatting with your codebase.
When you ask a question Ziya sends your entire codebase as context to the LLM, along with your question and any chat history.
> Entering new AgentExecutor chain...
Reading user's current codebase: /Users/vkrishnaprasad/personal_projects/ziya
ziya
├── .gitignore
├── DEVELOPMENT.md
├── LICENSE
├── README.md
└── pyproject.toml
app
├── __init__.py
├── main.py
└── server.py
...
--exclude
: Comma-separated list of files or directories or file suffix patterns to exclude from the codebase. Eg: "--exclude 'tst,build,*.py'"
--profile
: AWS profile to use for the Bedrock LLM.
--model
: The AWS Bedrock Model to use, one of sonnet3.7
(default), sonnet
, haiku
or opus
.
--port
: The port number for frontend app. Default is 6969
.
--max-depth
: Maximum depth for folder structure traversal. Default is 15
.
ziya --exclude='tst,build,*.py' --profile=ziya --model=sonnet3.7 --port=8080
FAQs
Unknown package
We found that ziya demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.