Research
Security News
Malicious PyPI Package ‘pycord-self’ Targets Discord Developers with Token Theft and Backdoor Exploit
Socket researchers uncover the risks of a malicious Python package targeting Discord developers.
@holaluz/cosmopolitan
Advanced tools
[![npm](https://img.shields.io/npm/v/@holaluz/cosmopolitan.svg)](https://img.shields.io/npm/v/@holaluz/cosmopolitan.svg) [![deploy](https://github.com/holaluz/cosmopolitan/workflows/Build%20and%20Deploy/badge.svg)](https://github.com/holaluz/cosmopolitan/
Cosmopolitan is a repository to share the header and menu for the internal sales tool.
The storybook with component examples is available here.
The package is hosted here on Github itself as it is a private package.
$ npm install @holaluz/cosmopolitan --save
Clone the repo and install node dependencies:
$ npm install
$ npm start
# run storybook
$ npm start
# run unit tests
$ npm test
# run unit tests with watch mode enabled
$ npm run test:watch
Every commit into master automatically triggers GH pages deploy and Semantic Release check.
cosmopolitan uses Semantic Release to handle the release pipeline.
Triggering a new release will create the associated Git tag, the GitHub release entry, and publish a new version on npm.
In order to trigger a new version, make sure you add the appropriate prefix and message to the squashed commit. It is based on the Angular Commit Message Conventions. In short:
# Creates a patch release (v1.0.0 -> v1.0.1)
> fix: commit message
# Creates a feature release (v1.0.0 -> v1.1.0)
> feat: commit message
# Creates a breaking release (v1.0.0 -> v2.0.0)
> fix: commit message
>
> BREAKING CHANGE: explain the breaking change # "BREAKING CHANGE:" is what triggers the breaking release
There's no need to overcomplicate things here. Keep it simple: fix
, feat
, and chore
(plus BREAKING CHANGE
) should be enough for now.
FAQs
[![npm](https://img.shields.io/npm/v/@holaluz/cosmopolitan.svg)](https://img.shields.io/npm/v/@holaluz/cosmopolitan.svg) [![deploy](https://github.com/holaluz/cosmopolitan/workflows/Build%20and%20Deploy/badge.svg)](https://github.com/holaluz/cosmopolitan/
The npm package @holaluz/cosmopolitan receives a total of 0 weekly downloads. As such, @holaluz/cosmopolitan popularity was classified as not popular.
We found that @holaluz/cosmopolitan demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover the risks of a malicious Python package targeting Discord developers.
Security News
The UK is proposing a bold ban on ransomware payments by public entities to disrupt cybercrime, protect critical services, and lead global cybersecurity efforts.
Security News
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.