
Research
NPM targeted by malware campaign mimicking familiar library names
Socket uncovered npm malware campaign mimicking popular Node.js libraries and packages from other ecosystems; packages steal data and execute remote code.
org.webjars.npm:gulp-debug
Advanced tools
Debug Vinyl file streams to see what files are run through your Gulp pipeline
$ npm install --save-dev gulp-debug
const gulp = require('gulp');
const debug = require('gulp-debug');
gulp.task('default', () =>
gulp.src('foo.js')
.pipe(debug({title: 'unicorn:'}))
.pipe(gulp.dest('dist'))
);
Type: Object
Type: string
Default: gulp-debug:
Give it a custom title so it's possible to distinguish the output of multiple instances logging at once.
Type: boolean
Default: true
By default only relative paths are shown. Turn off minimal mode to also show cwd
, base
, path
.
The stat
property will be shown when you run gulp in verbose mode: gulp --verbose
.
Type: boolean
Default: true
Print filenames.
Type: boolean
Default: true
Print the file count.
Type: Function
Default: fancy-log
Provide your own logging utility in place of fancy-log. The message is passed as a string in the first argument. Note that ANSI colors may be used in the message.
MIT © Sindre Sorhus
FAQs
WebJar for gulp-debug
We found that org.webjars.npm:gulp-debug demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovered npm malware campaign mimicking popular Node.js libraries and packages from other ecosystems; packages steal data and execute remote code.
Research
Socket's research uncovers three dangerous Go modules that contain obfuscated disk-wiping malware, threatening complete data loss.
Research
Socket uncovers malicious packages on PyPI using Gmail's SMTP protocol for command and control (C2) to exfiltrate data and execute commands.