
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
@conventional-changelog/git-client
Advanced tools
Simple git client for conventional changelog packages.
Simple git client for conventional changelog packages.
Install • Usage • API# pnpm
pnpm add @conventional-changelog/git-client conventional-commits-filter conventional-commits-parser
# yarn
yarn add @conventional-changelog/git-client conventional-commits-filter conventional-commits-parser
# npm
npm i @conventional-changelog/git-client conventional-commits-filter conventional-commits-parser
Note: conventional-commits-filter and conventional-commits-parser are required only if you need ConventionalGitClient#getCommits method.
import {
GitClient,
ConventionalGitClient
} from '@conventional-changelog/git-client'
// Basic git client
const client = new GitClient(process.cwd())
await client.add('package.json')
await client.commit({ message: 'chore: release v1.0.0' })
await client.tag({ name: 'v1.0.0' })
await client.push('master')
// Conventional git client, which extends basic git client
const conventionalClient = new ConventionalGitClient(process.cwd())
console.log(await conventionalClient.getVersionFromTags()) // v1.0.0
new GitClient(cwd: string)Create a wrapper around git CLI instance.
getRawCommits(params?: GitLogParams): AsyncIterable<string>Get raw commits stream.
getTags(): AsyncIterable<string>Get tags stream.
getLastTag(): Promise<string>Get last tag.
checkIgnore(file: string): Promise<boolean>Check file is ignored via .gitignore.
add(files: string | string[]): Promise<void>Add files to git index.
commit(params: GitCommitParams): Promise<void>Commit changes.
tag(params: GitTagParams): Promise<void>Create a tag for the current commit.
getCurrentBranch(): Promise<string>Get current branch name.
push(branch: string): Promise<void>Push changes to remote.
verify(rev: string): Promise<string>Verify rev exists.
getConfig(key: string): Promise<string>Get config value by key.
new ConventionalGitClient(cwd: string)Wrapper around Git CLI with conventional commits support.
getCommits(params?: ConventionalGitLogParams, parserOptions?: ParserStreamOptions): AsyncIterable<Commit>Get parsed commits stream.
getSemverTags(params?: GitTagsLogParams): AsyncIterable<string>Get semver tags stream.
getLastSemverTag(params?: GetSemverTagsParam): Promise<string>Get last semver tag.
getVersionFromTags(params?: GetSemverTagsParams): Promise<string | null>Get current sematic version from git tags.
MIT © Dan Onoshko
FAQs
Simple git client for conventional changelog packages.
The npm package @conventional-changelog/git-client receives a total of 2,137,562 weekly downloads. As such, @conventional-changelog/git-client popularity was classified as popular.
We found that @conventional-changelog/git-client demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.