
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@actions/glob
Advanced tools
@actions/globYou can use this package to search for files matching glob patterns.
Relative paths and absolute paths are both allowed. Relative paths are rooted against the current working directory.
const glob = require('@actions/glob');
const patterns = ['**/tar.gz', '**/tar.bz']
const globber = await glob.create(patterns.join('\n'))
const files = await globber.glob()
const glob = require('@actions/glob');
const globber = await glob.create('**', {followSymbolicLinks: false})
const files = await globber.glob()
When dealing with a large amount of results, consider iterating the results as they are returned:
const glob = require('@actions/glob');
const globber = await glob.create('**')
for await (const file of globber.globGenerator()) {
console.log(file)
}
Glob follows symbolic links by default. Following is often appropriate unless deleting files.
Users may want to opt-out from following symbolic links for other reasons. For example, excessive amounts of symbolic links can create the appearance of very, very many files and slow the search.
When an action allows a user to specify input patterns, it is generally recommended to allow users to opt-out from following symbolic links.
Snippet from action.yml:
inputs:
files:
description: 'Files to print'
required: true
follow-symbolic-links:
description: 'Indicates whether to follow symbolic links'
default: true
And corresponding toolkit consumption:
const core = require('@actions/core')
const glob = require('@actions/glob')
const globOptions = {
followSymbolicLinks: core.getInput('follow-symbolic-links').toUpper() !== 'FALSE'
}
const globber = glob.create(core.getInput('files'), globOptions)
for await (const file of globber.globGenerator()) {
console.log(file)
}
Patterns *, ?, [...], ** (globstar) are supported.
With the following behaviors:
. may be included in the results/ and \ both supported on WindowsSupports basic tilde expansion, for current user HOME replacement only.
Example:
~ may expand to /Users/johndoe~/foo may expand to /Users/johndoe/fooPatterns that begin with # are treated as comments.
Leading ! changes the meaning of an include pattern to exclude.
Multiple leading ! flips the meaning.
Wrapping special characters in [] can be used to escape literal glob characters
in a file name. For example the literal file name hello[a-z] can be escaped as hello[[]a-z].
On Linux/macOS \ is also treated as an escape character.
The 'glob' package is a popular library for file matching using glob patterns. It is widely used in the Node.js ecosystem and offers similar functionality to @actions/glob, such as pattern matching and file exclusion. However, @actions/glob is specifically optimized for use in GitHub Actions workflows.
The 'fast-glob' package is another alternative for file matching using glob patterns. It is known for its performance and efficiency, especially with large sets of files. Compared to @actions/glob, 'fast-glob' offers faster matching and additional options for customization.
The 'minimatch' package provides a minimalistic approach to glob pattern matching. It is a lightweight library that focuses on simplicity and ease of use. While it offers similar functionality to @actions/glob, it may not have the same level of integration with GitHub Actions workflows.
FAQs
Actions glob lib
The npm package @actions/glob receives a total of 467,283 weekly downloads. As such, @actions/glob popularity was classified as popular.
We found that @actions/glob demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.