Security News
PyPI’s New Archival Feature Closes a Major Security Gap
PyPI now allows maintainers to archive projects, improving security and helping users make informed decisions about their dependencies.
@thebespokepixel/cordial
Advanced tools
A reusuable module mastering and publishing system, built on top of Rollup, Babel 6, Gulp 4 and git-flow-avh
A system for creating and authoring on OS X and seamlessly deploying to Linux and OS X. With full es2015 with useful included extensions up to es2017, incuding async/await, and support of es2015 import/export module functionality.
Under the hood it uses Rollup, Babel, CoffeeScript, xo-tidy, gulp, git, git-flow-avh, @thebespokepixel/guppy (a customised fork of guppy with git-flow-avh hook support), shelljs, xo, ava and a handful of other gulp plugins to provide a single build system easily deployable across projects easily while being deeply customisable.
A feature of cordial is the ability to publish multi-personality modules for Node v4, v5 and v6 that expose as much native es2015 as each version supports and allows the inclusion of native es2015 code to allow tools such as Rollup, SystemJS and Traceur to perform tree-shaking and code-base optimisation.
Much more in depth docs to follow…
git
. Apple's default in OS X 10.11 is fine, or brew install git
brew install git-flow-avh
. Peter Van Der Does' fork of git flow.Before installing, make sure that your destination repository has been git-flow enabled...
> git flow init --defaults
You don't need to use the default branch names, but unless you have particularly complex naming requirements, there's not much reason not to.
Tower 2 Incredibly powerful and flexible Git GUI for OS X. With cordial, I can completely automate my release process to Github and npm without ever touching the command line.
FAQs
Syrupy confection for gulp workflows
The npm package @thebespokepixel/cordial receives a total of 0 weekly downloads. As such, @thebespokepixel/cordial popularity was classified as not popular.
We found that @thebespokepixel/cordial demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
PyPI now allows maintainers to archive projects, improving security and helping users make informed decisions about their dependencies.
Research
Security News
Malicious npm package postcss-optimizer delivers BeaverTail malware, targeting developer systems; similarities to past campaigns suggest a North Korean connection.
Security News
CISA's KEV data is now on GitHub, offering easier access, API integration, commit history tracking, and automated updates for security teams and researchers.