
Security News
PodRocket Podcast: Inside the Recent npm Supply Chain Attacks
Socket CEO Feross Aboukhadijeh discusses the recent npm supply chain attacks on PodRocket, covering novel attack vectors and how developers can protect themselves.
@comall/dingtalk-notice
Advanced tools
钉钉消息推送插件(搭配 Gitlab CI CD
使用), CI CD 完成以后在钉钉群中发布消息并@相关人员(CICD 发起者 以及 配置的测试人员)
需要在 Gitlab 对应项目下的 CI / CD Settings
> Variables
,进行以下配置
key | Value | description |
---|---|---|
CUSTOM_DD_ACCESS_TOKEN | xxxx | 钉钉自定义机器人 ACCESS_TOKEN |
CUSTOM_DD_SECRET | xxx | 钉钉自定义机器人 SECRET |
CUSTOM_DEFAULT_PHONE | 18888888888 | 默认通知手机号 |
CUSTOM_TESTER_PHONE | Xxxx | 测试人员手机号,多个 , 分隔开(18888888888,18888888889) |
test_preson_account | xxxx | 对应开发人员 gitlab 账号,用于在钉钉中艾特相关人员(因为钉钉中艾特功能需要手机号参数) |
FAQs
We found that @comall/dingtalk-notice demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Socket CEO Feross Aboukhadijeh discusses the recent npm supply chain attacks on PodRocket, covering novel attack vectors and how developers can protect themselves.
Security News
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
Product
Socket Firewall is a free tool that blocks malicious packages at install time, giving developers proactive protection against rising supply chain attacks.