
Research
wget to Wipeout: Malicious Go Modules Fetch Destructive Payload
Socket's research uncovers three dangerous Go modules that contain obfuscated disk-wiping malware, threatening complete data loss.
bulk-update-versions
Advanced tools
Script to bulk update versions matching a certain pattern.
$ npm install --save bulk-update-versions
Certain dependencies are usually released and updated in bulk as they follow a single Lerna version bump. Updating those packages can get quite verbose, as you need to check which packages have been released, find the right version, and update them.
To make this process simpler, you can use this package to bump all versions of dependencies matching the given pattern. The script will make sure that the versions of the packages matching the given pattern do exist, and bump the version only then.
$ bulk-update-versions --match '^@babel/(.*)' 7.9.2
latest
versionIf you want to update all the matching packages to their latest
version, you can pass the --force-latest
flag instead of a fixed version.
$ bulk-update-versions --match '^@babel/(.*)' --force-latest
FAQs
Script to bulk update versions matching a certain pattern
The npm package bulk-update-versions receives a total of 91 weekly downloads. As such, bulk-update-versions popularity was classified as not popular.
We found that bulk-update-versions demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket's research uncovers three dangerous Go modules that contain obfuscated disk-wiping malware, threatening complete data loss.
Research
Socket uncovers malicious packages on PyPI using Gmail's SMTP protocol for command and control (C2) to exfiltrate data and execute commands.
Product
We redesigned Socket's first logged-in page to display rich and insightful visualizations about your repositories protected against supply chain threats.