
Security News
PodRocket Podcast: Inside the Recent npm Supply Chain Attacks
Socket CEO Feross Aboukhadijeh discusses the recent npm supply chain attacks on PodRocket, covering novel attack vectors and how developers can protect themselves.
@gh-bot/core
Advanced tools
Looking for a simpler way to create bots? Try @gh-bot/cli, which allows writing simple scripts that trigger on commands.
@gh-bot/core is a simple framework to allow bot creation on GitHub. You can let the bot respond to multiple events like this:
const bot = new GhBot(token, repo, github_secret);
bot.on('command', (command, ghBot) => {
bot.comment("## Hello world!");
});
bot.on('push', (branch, ghBot) => {
bot.comment("## Hello world!");
});
bot.listen(port);
port
is port the bot listens on.token
is the GitHub access token of the botrepo
is an arry of repo owner and repo name, like ["gh-bot", "core"]github_secret
is the secret to use for the webhooks.If you already having existing botio code and don't want to rewrite it for @gh-bot/cli, you can use @gh-bot/botio which provides the Bot.io API with a modern base.
FAQs
GitHub bot framework
We found that @gh-bot/core demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Socket CEO Feross Aboukhadijeh discusses the recent npm supply chain attacks on PodRocket, covering novel attack vectors and how developers can protect themselves.
Security News
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
Product
Socket Firewall is a free tool that blocks malicious packages at install time, giving developers proactive protection against rising supply chain attacks.