Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Automated compilation and deployment to gh-pages
Here are examples of github repositories that take advantage of autopages, and the servers that power them.
master
or autopages
branch is updated, the gh-pages
branch is redeployed automaticallyindex.jade
tells autopages to parse the most recent readme file on each commitgh-pages
branch, which is hosted at http://mathisonian.github.io/autopages/ap-content
branch are parsed and inserted into the final html files.This project is meant to be self hosted on Heroku or similar, so that you maintain control over who has push access to your repositories.
In general it assumes convention over configuration to make the setup process as painless as possible.
There are two types of github pages repositories. For each of them it assumes that three branches exist:
This is dynamic content that is going to be displayed on your github pages. For example, if your project is a blog, it would include blog posts. If it is a software library, it would be the code and readme (you can choose to display -- perhaps just the readme -- in the tranformation branch).
This looks like a static client side website. It should follow this folder structure
$ tree
.
├── images
│ └── logo.png
├── js
│ └── app.js
├── stylesheets
│ └── app.scss
└── templates
└── index.jade
although can be significantly more complex than this. This is discussed later.
This is where the compiled static site go. Autopages will automatically commit and push this branch back to github every time there is a new commit on the input branch or the transformation branch.
For repos in the <username>.github.io
style, the following branch name conventions are enforced:
ap-content
autopages
master
Any other repos will follow the convention of
master
autopages
gh-pages
fork mathisonian-autopages and update it to watch your repositories.
Install the module with: npm install autopages
. You can create a new repo for this and in the main file write
var Autopages = require('autopages');
// be sure to replace this with your own api key.
// it must have access to repos and webhooks
var autopages = new Autopages('GITHUB_API_KEY');
autopages
.register('username/repo') // adds a webhook to the repo and listens for commit events
.then(function(processor) {
processor.use(/* use autopages plugins here */);
});
Thats it. Then, deploy it to heroku, and on heroku set the environmental variable URL
so that
it knows where to tell github to point a new webhook to.
Out of the box autopages works with the following stack
and will handle deploying custom fonts and images as well. If you want to use different software, this can be acheived through plugins.
Anyone can write a plugin for autopages. For example, see https://github.com/mathisonian/autopages-browserify.
Plugins are based on gulp tasks, and are expected to be in the format like this:
processor.use({
GULP_TASK_NAME: function(inputPath, outputPath) {
return /* return the gulp task here.*/
}
});
autopages will handle passing in the correct input and output paths to your function.
Please submit a PR if you publish a plugin
More documentation coming soon. In the meantime feel free to contact the author.
Copyright (c) 2014 Matthew Conlen. Licensed under the MIT license.
FAQs
Automated compilation and deployment to gh-pages
The npm package autopages receives a total of 3 weekly downloads. As such, autopages popularity was classified as not popular.
We found that autopages demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.