
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@postxl/sync
Advanced tools
PostXL Sync is a utility script that helps you sync changes you make inside a project to the PostXL template in this monorepository. It manages a tracking branch in this monorepo for each active PostXL project and syncs changes to the tracked files from a
PostXL Sync is a utility script that helps you sync changes you make inside a project to the PostXL template in this monorepository. It manages a tracking branch in this monorepo for each active PostXL project and syncs changes to the tracked files from a particular project with the tracking branch.
NOTE: It syncs changes with the tracking branch. The merging of the tracking branch with the main branch of the template is left to the manager of PXLTemplate tool.
NOTE: Because the tool syncs with the tracking branch, we don't have to handle the actual versioning of the template. Tools don't update projects automatically. The person responsible for the project triggers the update and checks its validity when PXLTemplate gets update. Other tools in our stack can help verify that everything works correctly. There is no concept of versioning of the template.
Sync takes care of two things:
It does both of these things whenever it runs, usually on every commit to the main branch of a project.
You should use this package inside a GitHub Action that runs on every commit to the main branch of your project.
name: Sync changes to PostXL template
on:
push:
branches:
- main
jobs:
sync:
- name: Checkout Main
uses: actions/checkout@v3
with:
fetch-depth: 0
- name: Setup Node Environment
uses: actions/setup-node@v3
with:
node-version-file: '.nvmrc'
cache: 'pnpm'
- name: Sync
run: pnpx @postxl/sync
env:
# NOTE: This token needs to have permission to access `postxl` repository!
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITHUB_REPOSITORY: ${{ github.repository }}
COMMIT_SHA: ${{ github.sha }}
FAQs
PostXL Sync is a utility script that helps you sync changes you make inside a project to the PostXL template in this monorepository. It manages a tracking branch in this monorepo for each active PostXL project and syncs changes to the tracked files from a
We found that @postxl/sync demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.