Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
changelog-tool
Advanced tools
This repository contains a simple tool for reading and manipulating changelog files.
This tool currently expects to work with a file named 'changelog.md' in the current working directory. This is a markdown file that looks like this:
0.4.0 (????-??-??)
------------------
* Feature A
* Bugfix 3
0.3.0 (2023-02-08)
------------------
* First public release!
Questionmarks for the date indicate an unreleased version.
npm install changelog-tool --save-dev
To tool can be used programmatically and with the CLI. The CLI has the following commands:
npx changelog init - Create a new, empty npx changelog.
npx changelog add -m [message] - Adds a new line to the npx changelog.
npx changelog release - Marks the current npx changelog as released.
npx changelog show - Show the last npx changelog.
npx changelog show [version] - Show the npx changelog of a specific version.
npx changelog list - List all versions in the npx changelog.
npx changelog format - Reformats the npx changelog in the standard format.
Easiest is to just run:
npx changelog add -m "Bug fix"
This will automatically add a line to the latest unreleased version. If there is no unreleased version, it will create a new patch version.
If the change should cause a minor or major version bump, you can specify the these options too:
npx changelog add --minor -m "New feature"
npx changelog add --major -m "Backwards compatibility break"
These settings will automatically adjust the version string of the most recent unreleased version.
FAQs
A CLI tool for manipulating changelogs
The npm package changelog-tool receives a total of 0 weekly downloads. As such, changelog-tool popularity was classified as not popular.
We found that changelog-tool demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.