Security News
Node.js EOL Versions CVE Dubbed the "Worst CVE of the Year" by Security Experts
Critics call the Node.js EOL CVE a misuse of the system, sparking debate over CVE standards and the growing noise in vulnerability databases.
@thebespokepixel/cordial
Advanced tools
A reusuable module mastering and publishing system, built on top of Rollup, Babel 6, Gulp 4 and git-flow-avh
A system for creating and authoring on OS X and seamlessly deploying to Linux and OS X. With full es2015 and useful included extensions up to es2017, incuding async/await, and support of es2015 import/export module functionality.
Under the hood it uses Rollup, Babel, CoffeeScript, xo-tidy, gulp, git, git-flow-avh, @thebespokepixel/guppy (a customised fork of guppy with git-flow-avh hook support), shelljs, xo, ava and a handful of other gulp plugins to provide a single build system easily deployable across projects easily while being deeply customisable.
A feature of cordial is the ability to publish multi-personality modules for Node v4, v5 and v6 that expose as much native es2015 as each version supports and allows the inclusion of native es2015 code to allow tools such as Rollup, SystemJS and Traceur to perform tree-shaking and code-base optimisation.
Much more in depth docs to follow…
git
. Apple's default in OS X 10.11 is fine, or brew install git
brew install git-flow-avh
. Peter Van Der Does' fork of git flow.Before installing, make sure that your destination repository has been git-flow enabled...
> git flow init --defaults
You don't need to use the default branch names, but unless you have particularly complex naming requirements, there's not much reason not to.
Tower 2 Incredibly powerful and flexible Git GUI for OS X. With cordial, I can completely automate my release process to Github and npm without ever touching the command line.
FAQs
Syrupy confection for gulp workflows
We found that @thebespokepixel/cordial demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Critics call the Node.js EOL CVE a misuse of the system, sparking debate over CVE standards and the growing noise in vulnerability databases.
Security News
cURL and Go security teams are publicly rejecting CVSS as flawed for assessing vulnerabilities and are calling for more accurate, context-aware approaches.
Security News
Bun 1.2 enhances its JavaScript runtime with 90% Node.js compatibility, built-in S3 and Postgres support, HTML Imports, and faster, cloud-first performance.