
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
@forgettingpasswords/netlify-cms
Advanced tools
An extensible, open source, Git-based, React CMS for static sites.
A CMS for static site generators. Give non-technical users a simple way to edit and add content to any site built with a static site generator.
Netlify CMS is a single-page app that you pull into the /admin part of your site.
It presents a clean UI for editing content stored in a Git repository.
You setup a YAML config to describe the content model of your site, and typically tweak the main layout of the CMS a bit to fit your own site.
When a user navigates to /admin/ they'll be prompted to login, and once authenticated
they'll be able to create new content or edit existing content.
Read more about Netlify CMS Core Concepts.
The Netlify CMS can be used in two different ways.
Netlify CMS has a Gitter community where members of the community hang out and share things about the project, as well as give and receive support.
New contributors are always welcome! Check out CONTRIBUTING.md to get involved.
This project adheres to Semantic Versioning. Every release is documented on the Github Releases page.
Netlify CMS is released under the MIT License. Please make sure you understand its implications and guarantees.
These services support Netlify CMS development by providing free infrastructure.
FAQs
An extensible, open source, Git-based, React CMS for static sites.
We found that @forgettingpasswords/netlify-cms demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.