
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
commitlive
Advanced tools
Probably the most elegant way to make a conventional commit on the command line
tab completion, placeholders and livly prompt: this gives the user enough hints to make a better commit, with the help of repll
find issues for you: when you start typing # with a number, we will search for issues on github, it's based on gh cli, make sure it's installed and configured
conventional commit lint: while you are typing, we lint it for you using the great commitlint(!NOTE: When linting, we won't prompt <body> & <footer> as an input, this avoids overwhelming output message)
focus more on typing rather than choosing: some other commit tools pop up prompts for the user to select, whereas in commitlive you just type something and press tab to complete, which I think is closer to the way we interact with command line
very close to git commit command: under the hood, commitlive just run git commit command for you with the flag and commit you provided, and flag is always same as git commit
NOTE! You must have NodeJS v13.5.0+(v12.16.0+) installed in order to get commitlive up and running
Install it globally or run it directly using npx
npm i -g commitlive
npx commitlive
Run commitlive to commit your staged changes:
commitlive -m
Or make them staged while committing:
commitlive -am
You may have noticed, it's same as git commit, quite easy to grasp its usage
Finally, be a good commitzen
FAQs
write conventional commits livly
We found that commitlive demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.