
Security News
CISA Extends MITRE Contract as Crisis Accelerates Alternative CVE Coordination Efforts
CISA extended MITRE’s CVE contract by 11 months, avoiding a shutdown but leaving long-term governance and coordination issues unresolved.
@getvolume/react-native
Advanced tools
React native components for Volume.
For instructions please see Documentation Site
The site is password protected, if you do not know your password already please get in touch!
This repository uses the changesets workflow for releases.
To release, create a PR as normal, you then have two options to create a changeset which will trigger a release:
Run yarn changeset
and follow the prompts, this will create a changeset file in the .changeset
directory on your PR and increment the package version.
Use the changeset bot which comments on your PR with instructions on how to create a changeset
The simpler option is to use the PR bot, click the link to create a new changeset.
This will open the github UI to create a new changeset, you can then commit this changeset to your PR.
Once your PR is merged, the changeset github action will create a PR with the new version and changelog.
Simply merge this to main and the new version will be published to npm.
FAQs
React Native
We found that @getvolume/react-native demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
CISA extended MITRE’s CVE contract by 11 months, avoiding a shutdown but leaving long-term governance and coordination issues unresolved.
Product
Socket's Rubygems ecosystem support is moving from beta to GA, featuring enhanced security scanning to detect supply chain threats beyond traditional CVEs in your Ruby dependencies.
Research
The Socket Research Team investigates a malicious npm package that appears to be an Advcash integration but triggers a reverse shell during payment success, targeting servers handling transactions.