Research
Security News
Threat Actor Exposes Playbook for Exploiting npm to Build Blockchain-Powered Botnets
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
all-contributors
Advanced tools
Call for translators! We're looking for translators to help translate this spec for everyone!
한국어 | 中文 | Bahasa Indonesia | Deutsch | Polskie | |
English | Português | Español | Français | Русский | 日本語 |
This is a specification for recognizing contributors to an open source project in a way that rewards each and every contribution, not just code.
The basic idea is this:
Use the project README (or another prominent public documentation page in the project) to recognize the contributions of members of the project community.
People are giving themselves and their free time to contribute to open source projects in so many ways, so we believe everyone should be praised for their contributions (code or not).
Below is an example of how using the all-contributors spec table can recognize all contributors
You can use the @all-contributors bot 🤖 to automate acknowledging contributors to your open source projects
The specification is detailed on allcontributors.org
The Emoji Key ✨ (and Contribution Types) can be found on allcontributors.org
If you've ever wanted to contribute to open source, and a great cause, now is your chance!
See the contributing docs for more information
Thanks goes to these wonderful people (emoji key):
This project follows the all-contributors specification. Contributions of any kind are welcome!
FAQs
✨ Recognize all contributors, not just the ones who push code ✨
The npm package all-contributors receives a total of 9 weekly downloads. As such, all-contributors popularity was classified as not popular.
We found that all-contributors demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
Security News
NVD’s backlog surpasses 20,000 CVEs as analysis slows and NIST announces new system updates to address ongoing delays.
Security News
Research
A malicious npm package disguised as a WhatsApp client is exploiting authentication flows with a remote kill switch to exfiltrate data and destroy files.