
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Add Google Sheets as live resources in Device Magic.
Device Magic users can upload .xlsx files to be referenced within their mobile forms. This project is aimed at automating the same process for Google Sheets to increase the flexibility of resources.
$ gem install dm_live_resources
To add a Google Sheet as a Resource, in terminal execute:
$ ruby add_resource --gs-api-key="Google Drive API Key" --gs-identifier="Google Sheet Identifier" --gs-sheets="Sheets in workbook to be tracked for changes" --dm-api-key="Device Magic API Key"
The first time this script is ran, a 'Resources.db' file will be created in the same directory with a table for the resource data. The Google Sheet will then be added to the Device Magic organization in .xlsx format. Each time thereafter, an additional table will be added to the same database.
$ ruby update_db
This will check to see if any changes have been made within the sheets you specified previously for your resources. If there are changes, Device Magic will be updated with a new copy of the resource.
After checking out the repo, run bin/setup
to install dependencies. Then, run rake test
to run the tests. You can also run bin/console
for an interactive prompt that will allow you to experiment.
To install this gem onto your local machine, run bundle exec rake install
. To release a new version, update the version number in version.rb
, and then run bundle exec rake release
, which will create a git tag for the version, push git commits and tags, and push the .gem
file to rubygems.org.
Bug reports and pull requests are welcome on GitHub at https://github.com/aseli1/dm_live_resources.
The gem is available as open source under the terms of the MIT License.
FAQs
Unknown package
We found that dm_live_resources demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.