Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
@andrejewski/atom-feed-generator
Advanced tools
The wrapper around the NPM
feed
package I use for my website feeds
npm install @andrejewski/atom-feed-generator
Improves upon the feed
package by:
Feedback on the generated output is appreciated.
I didn't really think that I'd have much to improve about the most popular feed reader generator package in the year 2022 but there was enough I did to work around feed
that I thought it was worth sharing.
If I'd had the time I would have approached this as a clean room exercise, but I will document what I learn about Atom feed generators going forward in this repository.
FAQs
Generate better Atom feeds
We found that @andrejewski/atom-feed-generator demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.