
Security News
Another Round of TEA Protocol Spam Floods npm, But It’s Not a Worm
Recent coverage mislabels the latest TEA protocol spam as a worm. Here’s what’s actually happening.
@semantic-release-extras/github-comment-specific
Advanced tools
[![Build Status]](https://github.com/semantic-release-extras/github-comment-specific/actions/workflows/release.yml)
This is a drop-in replacement for the standard @semantic-release/github plugin. It exists to add specificity to the GitHub issue and PR comments, so instead of commenting that
This PR is included in version {version}
it comments
This PR is included in version {package}@{version}
I agree, this seems like a small improvement. However, when using semantic-release with a multirepo1 the default behavior adds several comments like this to a PR:
which is downright confusing.
With @semantic-release-extras/github-comment-specific, the comments look like:
Much better!
npm install --save-dev --save-exact @semantic-release-extras/github-comment-specific
@semantic-release-extras/github-comment-specific is just a wrapper, so it inherits the API contract of @semantic-release/github.
For example:
{
"plugins": [
"@semantic-release/commit-analyzer",
"@semantic-release/release-notes-generator",
"@semantic-release/npm",
"@semantic-release/git",
"@semantic-release-extras/github-comment-specific"
]
}
It may be possible to use the stock @semantic-release/github plugin with configuration like:
[
"@semantic-release/github",
{
"successComment": ":tada: This ${issue.pull_request ? 'PR is included' : 'issue has been resolved'} in version ${nextRelease.gitTag}</br></br>The release is available on [${releases[0].name}](${releases[0].url}) :tada:</br></br>Your **[semantic-release](https://github.com/semantic-release/semantic-release)** bot :package::rocket:"
}
]
Note: This configuration is untested.
However, the templating options offered by the stock plugin leave something to be desired. This template is not one-to-one with @semantic-release-extras/github-comment-specific in terms of features or flexibility.
Wouldn't it be better to upstream these changes?
Yep, definitely. The upstream repository has a high load:maintainers ratio at the moment, and this plugin exists here and now.
FAQs
[![Build Status]](https://github.com/semantic-release-extras/github-comment-specific/actions/workflows/release.yml)
We found that @semantic-release-extras/github-comment-specific demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Recent coverage mislabels the latest TEA protocol spam as a worm. Here’s what’s actually happening.

Security News
PyPI adds Trusted Publishing support for GitLab Self-Managed as adoption reaches 25% of uploads

Research
/Security News
A malicious Chrome extension posing as an Ethereum wallet steals seed phrases by encoding them into Sui transactions, enabling full wallet takeover.