
Security News
TeamPCP and BreachForums Launch $1,000 Contest for Supply Chain Attacks
TeamPCP and BreachForums are promoting a Shai-Hulud supply chain attack contest with a $1,000 prize for the biggest package compromise.
@types/semver
Advanced tools
TypeScript definitions for semver
npm install --save @types/semver
This package contains type definitions for semver (https://github.com/npm/node-semver).
Files were exported from https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/semver.
These definitions were written by Bart van der Schoor, BendingBender, Lucian Buzzo, Klaus Meinhardt, ExE Boss, and Piotr Błażejewicz.
This package provides functionality for comparing version numbers. While it offers similar version comparison capabilities, it lacks the broader feature set of semver, such as range checking and version parsing.
A simple package for comparing version strings. It is more lightweight than semver but does not support semantic versioning's pre-release and build metadata.
FAQs
TypeScript definitions for semver
The npm package @types/semver receives a total of 27,718,204 weekly downloads. As such, @types/semver popularity was classified as popular.
We found that @types/semver demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
TeamPCP and BreachForums are promoting a Shai-Hulud supply chain attack contest with a $1,000 prize for the biggest package compromise.

Security News
Packagist urges PHP projects to update Composer after a GitHub token format change exposed some GitHub Actions tokens in CI logs.

Research
GemStuffer abuses RubyGems as an exfiltration channel, packaging scraped UK council portal data into junk gems published from new accounts.