Are you sure the open-source React package (from npm) is malicious/risky?

Опубликовано: 12 Январь 2023
на канале: 650 AI Lab
469
26

Learn to identify if your JavaScript - React (NPM) is malicious or risky to use in your own JavaScript application.

Packj - The vetting tool 🚀 behind our "dependency firewall" to block malicious/risky open-source packages in your software supply chain
https://github.com/ossillate-inc/packj

Various Command Sample:
$ python main.py audit -t -p npm:react
$ python main.py audit -t -p npm:react-scripts
$ python main.py audit -t -f npm:package.json

== Video Timeline ==
(00:00) Quick Intro
(00:42) Quick tool overview
(03:33) Why the need?
(05:05) Packj installation
(06:20) How to audit Package?
(12:15) How to audit Package.json?
(17:06) End Credits

Please visit:
https://prodramp.com | @prodramp
  / prodramp  

Content Creator:
Avkash Chauhan (@avkashchauhan)
  / avkashchauhan  

Tags:
#python #ruby #react #developertools