
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Zrb allows you to write your automation tasks in Python and declaratively:
# Filename: zrb_init.py
from zrb import cli, Task, Group, IntInput
math = cli.add_group(Group("math", description="Math tools"))
math.add_task(Task(
name="add",
input=[
IntInput("a", description="First number"),
IntInput("b", description="Second number")
],
action=lambda ctx: ctx.input.a + ctx.input.b
))
Once defined, you will be able to access your automation tasks from the CLI, Web Interface, or via HTTP API.
For more complex scenario, you can also defined Task dependencies (upstreams) and retry mechanisms. You can also make a scheduled tasks, just like in Apache Airflow.
Furthermore, Zrb has some builtin tasks to manage monorepo, generate FastAPI application, or play around with LLM.
See the getting started guide for more information. Or just watch the demo:
You can install Zrb as a pip package by invoking the following command:
pip install --pre zrb
Alternatively, you can also use our installation script to install Zrb along with some prerequisites:
bash -c "$(curl -fsSL https://raw.githubusercontent.com/state-alchemists/zrb/refs/heads/1.0.0/install.sh)"
# bash -c "$(curl -fsSL https://raw.githubusercontent.com/state-alchemists/zrb/main/install.sh)"
You can submit bug reports and feature requests by creating a new issue on Zrb's GitHub Repositories. When reporting a bug or requesting a feature, please be sure to:
zrb version
)We will also welcome your pull requests and contributions.
Help Red Skull to click the donation button:
Madou Ring Zaruba (魔導輪ザルバ, Madōrin Zaruba) is a Madougu which supports bearers of the Garo Armor. (Garo Wiki | Fandom)
FAQs
Your Automation Powerhouse
We found that zrb demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.