
Security News
CVE Volume Surges Past 48,000 in 2025 as WordPress Plugin Ecosystem Drives Growth
CVE disclosures hit a record 48,185 in 2025, driven largely by vulnerabilities in third-party WordPress plugins.
@drovp/run
Advanced tools
Drovp plugin to execute one or a series of console commands on dropped items.
Features:
Templates are JavaScript template literals allowing embedded expressions.
All variables and utilities available in templates are documented in profile's instructions.
Basic command template using a variable and a utility call:
binary-name "${path}" --param ${uid(5)}
You can use new lines and indentation to visually separate parameters, they'll be removed when expanding the template:
binary-name "${path}"
--param ${uid(5)}
--param2 ${Time(starttime).format(YYYY)}
New line terminal escapes \ and ^ are also supported, so you can just paste in already existing commands.
Expressions are powerful:
binary-name
"${stdout.match(/^\[path\]([^\n]+)$/m)[1].trim()}"
--param "${filename.toUpperCase()}"
stdout is a reference to the stdout output of the previous command. Other stdouts are available on the stdouts[] array. In the example above, we are using regular expression to extract path from an stdout line such as [path] /path/to/file to use in the current command.
You can enable bulked mode to group all items dropped into the profile into a single operation.
Default behavior is to split all dropped items into separate operations.
These items will then be available inside templates on the inputs[] array, which can then be used to do stuff like concatenating dropped files using ffmpeg:
ffmpeg
-i "concat:${inputs.map(f => f.basename).join('|')}"
-codec copy
"${inputs[0].filename}-concat.${inputs[0].ext}"
Example above requires command CWD to be set to ${commondir}.
FAQs
Execute one or multiple console commands on dropped items.
We found that @drovp/run demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
CVE disclosures hit a record 48,185 in 2025, driven largely by vulnerabilities in third-party WordPress plugins.

Security News
Socket CEO Feross Aboukhadijeh joins Insecure Agents to discuss CVE remediation and why supply chain attacks require a different security approach.

Security News
Tailwind Labs laid off 75% of its engineering team after revenue dropped 80%, as LLMs redirect traffic away from documentation where developers discover paid products.