
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
@uphold/commitlint-config
Advanced tools
Shareable commitlint config enforcing Uphold's commit conventions.
This package ensures our commits follow our standard:
❯ npm i commitlint-config-uphold --save-dev
or with Yarn:
❯ yarn add commitlint-config-uphold --dev
Create .commitlintrc.yml
with:
extends: "@uphold/commitlint-config"
Verbs are detected using data from Wordnet provided by wordnet package.
The wordnet
database is large with more than 28 megabytes because it contains all the english words, including their definitions. To provide the smallest package possible, there's a script that generates a JSON file that contains the extracted english verbs from wordnet
. To update the generated JSON whenever wordnet
releases a new version, run:
❯ yarn update-wordnet-verbs
⚠️ The detection algorithm simply checks if the first word is an english word that may be used as a verb (in the simple-present tense). It does not account if the word is actually a verb in the context of the phrase. It would be possible to detect if it's actually used as a verb by using natural language processing techniques. However, they often give bad results.
FAQs
Shareable commitlint config enforcing Uphold's commit conventions
The npm package @uphold/commitlint-config receives a total of 633 weekly downloads. As such, @uphold/commitlint-config popularity was classified as not popular.
We found that @uphold/commitlint-config demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 9 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.