
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
commitlint_cetacea
Advanced tools
commitlint-cetacea支持配套的 commitlint 配置,用于对 git commit message 进行校验。
使用时,需要安装 @commitlint/cli:
npm install commitlint-cetacea @commitlint/cli --save-dev
在 commitlint.config.js 中集成本包:
module.exports = {
extends: ['commitlint-cetacea'],
};
可通过 husky 设置在 git commit 时触发 commitlint。
首先安装 husky:
npm install husky --save-dev
然后执行添加commit-msg:
npx husky add .husky/commit-msg 'npx commitlint --edit $1'
更多信息可参考 commitlint 文档。
FAQs
commitlint
We found that commitlint_cetacea demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.