
Product
Socket Firewall Now Blocks Malicious VS Code and Open VSX Extensions
Socket Firewall blocks malicious VS Code and Open VSX extensions before install, protecting developers from compromised editor marketplaces.
@xbghc/gitcode-cli
Advanced tools
GitCode 命令行工具 — 让仓库操作快人一步
npm i -g @xbghc/gitcode-cli
gitcode auth set-token YOUR_TOKEN
gitcode pr list # 就这么简单
需要 Node.js 22+。Token 获取:GitCode 访问令牌
# 一键切到 PR 分支,本地 review
gitcode pr checkout 123
# 快速创建 Issue
gitcode issue create -t "Bug: 登录失败" -b "复现步骤..."
# 关闭/重开 Issue
gitcode issue close 42
gitcode issue reopen 42
# 创建 PR
gitcode pr create --title "新功能" --head feature-branch
智能识别:在 GitCode 仓库目录下执行命令,自动读取 remote 信息,无需手动传 URL。
gitcode auth set-token <token> # 保存令牌
gitcode auth status # 查看状态
gitcode auth remove-token # 删除令牌
令牌优先级:环境变量 GITCODE_TOKEN > 配置文件
gitcode --help # 查看所有命令
gitcode pr --help # PR 相关命令
gitcode issue --help # Issue 相关命令
gitcode repo --help # 仓库相关命令
完整文档:docs/gitcode-cli
git clone https://github.com/xbghc/gitcode-actions.git
cd gitcode-actions
pnpm install && pnpm build
cd packages/gitcode-cli && pnpm link --global
MIT
FAQs
CLI for GitCode.
The npm package @xbghc/gitcode-cli receives a total of 7 weekly downloads. As such, @xbghc/gitcode-cli popularity was classified as not popular.
We found that @xbghc/gitcode-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Product
Socket Firewall blocks malicious VS Code and Open VSX extensions before install, protecting developers from compromised editor marketplaces.

Research
More than 140 Mastra npm packages were compromised in a supply chain attack that used a typosquatted dependency to deliver a cross-platform infostealer during installation.

Research
/Security News
A new npm package tests AI malware scanners with prompt injection, safety-triggering comments, context flooding, and obfuscated JavaScript.