
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
bun-scripty
Advanced tools
Bun-Scripty is a package that allows you to define npm scripts in separate TypeScript files, adapted to work with Bun. This project is inspired by and based on scripty by Test Double.
Bun-Scripty allows you to organize your npm scripts into separate TypeScript files, making them easier to maintain and manage. Instead of cluttering your package.json
with numerous script commands, you can create individual TypeScript script files for each command.
bun add bun-scripty
Create a scripts
directory in your project root (or customize the path, see Customizing Script Path).
Add your TypeScript script files in this directory. For example, scripts/test.ts
for a test
script.
Make your script files executable:
chmod +x scripts/test.ts
In your package.json
, use Bun-Scripty to run your scripts:
{
"scripts": {
"test": "bun-scripty"
}
}
Now, when you run bun run test
, Bun-Scripty will execute the scripts/test.ts
file.
This project is based on the excellent scripty package by Test Double. We'd like to express our gratitude for their solid script setup and structure, which served as the foundation for Bun-Scripty.
Contributions are welcome! Please feel free to submit a Pull Request.
FAQs
Scripty for Bun
The npm package bun-scripty receives a total of 6 weekly downloads. As such, bun-scripty popularity was classified as not popular.
We found that bun-scripty demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.