Security News
Maven Central Adds Sigstore Signature Validation
Maven Central now validates Sigstore signatures, making it easier for developers to verify the provenance of Java packages.
@holaluz/cosmopolitan
Advanced tools
[![npm](https://img.shields.io/npm/v/@holaluz/cosmopolitan.svg)](https://img.shields.io/npm/v/@holaluz/cosmopolitan.svg) [![deploy](https://github.com/holaluz/cosmopolitan/workflows/Build%20and%20Deploy/badge.svg)](https://github.com/holaluz/cosmopolitan/
Cosmopolitan is a repository to share the header and menu for the internal sales tool.
The storybook with component examples is available here.
The package is hosted here on Github itself as it is a private package.
$ npm install @holaluz/cosmopolitan --save
Clone the repo and install node dependencies:
$ npm install
$ npm start
# run storybook
$ npm start
# run unit tests
$ npm test
# run unit tests with watch mode enabled
$ npm run test:watch
Every commit into master automatically triggers GH pages deploy and Semantic Release check.
cosmopolitan uses Semantic Release to handle the release pipeline.
Triggering a new release will create the associated Git tag, the GitHub release entry, and publish a new version on npm.
In order to trigger a new version, make sure you add the appropriate prefix and message to the squashed commit. It is based on the Angular Commit Message Conventions. In short:
# Creates a patch release (v1.0.0 -> v1.0.1)
> fix: commit message
# Creates a feature release (v1.0.0 -> v1.1.0)
> feat: commit message
# Creates a breaking release (v1.0.0 -> v2.0.0)
> fix: commit message
>
> BREAKING CHANGE: explain the breaking change # "BREAKING CHANGE:" is what triggers the breaking release
There's no need to overcomplicate things here. Keep it simple: fix
, feat
, and chore
(plus BREAKING CHANGE
) should be enough for now.
FAQs
[![npm](https://img.shields.io/npm/v/@holaluz/cosmopolitan.svg)](https://img.shields.io/npm/v/@holaluz/cosmopolitan.svg) [![deploy](https://github.com/holaluz/cosmopolitan/workflows/Build%20and%20Deploy/badge.svg)](https://github.com/holaluz/cosmopolitan/
We found that @holaluz/cosmopolitan demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Maven Central now validates Sigstore signatures, making it easier for developers to verify the provenance of Java packages.
Security News
CISOs are racing to adopt AI for cybersecurity, but hurdles in budgets and governance may leave some falling behind in the fight against cyber threats.
Research
Security News
Socket researchers uncovered a backdoored typosquat of BoltDB in the Go ecosystem, exploiting Go Module Proxy caching to persist undetected for years.