Security News
Research
Supply Chain Attack on Rspack npm Packages Injects Cryptojacking Malware
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
A codemod engine for Node.js libraries (jscodeshift, ts-morph, etc.)
GitHub
·
Documentation
.
Community
The Codemod platform helps you create, distribute, and deploy codemods in codebases of any size.
The AI-powered, community-led codemods enable you to automate framework upgrades, large refactoring, and boilerplate programming with unparalleled speed and developer experience.
npm i -g codemod
For details on how to use the Codemod platform, check out our documentation.
The list
command can be used to list all codemods available in the Codemod Registry.
codemod list
codemod [codemod-name]
codemod next/13/app-router-recipe
The learn
command can be used to send the diff of the latest edited file to the Codemod Studio and have it automatically build an explainable and debuggable codemod.
codemod learn
After running this command, if any git diff exists, codemod
will use the diff as before/after snippets in the Codemod Studio.
The Codemod community can be found on Slack, where you can ask questions, share your feedback, and contribute to the community.
Our Code of Conduct applies to all Codemod community channels.
We collect anonymous usage data to improve our product. Collected data cannot be linked to individual users. We do not store personal data/code.
For more details and samples of collected data see our telemetry compliance considerations doc.
FAQs
A codemod engine for Node.js libraries (jscodeshift, ts-morph, etc.)
The npm package codemod receives a total of 4,676 weekly downloads. As such, codemod popularity was classified as popular.
We found that codemod demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.
Security News
Sonar’s acquisition of Tidelift highlights a growing industry shift toward sustainable open source funding, addressing maintainer burnout and critical software dependencies.