
Product
Introducing Supply Chain Attack Campaigns Tracking in the Socket Dashboard
Campaign-level threat intelligence in Socket now shows when active supply chain attacks affect your repositories and packages.
Generate a Code of Conduct for your project - Provided by Contributor Covenant
tl;dr Having a Code of Conduct is helpful in fostering and enforcing a friendly inclusive community.
Open source projects suffer from a startling lack of diversity, with dramatically low representation by women, people of color, and other marginalized populations. Part of this problem lies with the very structure of some projects: the use of insensitive language, thoughtless use of pronouns, assumptions of gender, and even sexualized or culturally insensitive names.
An easy way to begin addressing this problem is to be overt in our openness, welcoming all people to contribute, and pledging in return to value them as human beings and to foster an atmosphere of kindness, cooperation, and understanding.
A Code of Conduct can be one way to express these values.
Do not simply add the Contributor Covenant to your project and assume that any problems with civility, harassment, or discrimination will be solved.
$ npm install --global conduct
Usage
$ conduct
Options
--uppercase, -c Use uppercase characters (e.g. CODE-OF-CONDUCT.md)
--underscore, -u Use underscores instead of dashes (e.g. code_of_conduct.md)
You can also use this to update an existing Code of Conduct.
When generating a new Code of Conduct it will try to infer your email to use as contact email. If it can't, it will prompt for it. The email is persisted and only asked once. You can force update the email with conduct --email=your@email.com. When updating an existing Code of Conduct, it will use the existing contact email unless you pass the --email flag.
Contributor Code of Conduct. By participating in this project you agree to abide by its terms.
MIT © Sindre Sorhus
FAQs
Generate a Code of Conduct for your project - Provided by Contributor Covenant
The npm package conduct receives a total of 47 weekly downloads. As such, conduct popularity was classified as not popular.
We found that conduct demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Product
Campaign-level threat intelligence in Socket now shows when active supply chain attacks affect your repositories and packages.

Research
Malicious PyPI package sympy-dev targets SymPy users, a Python symbolic math library with 85 million monthly downloads.

Security News
Node.js 25.4.0 makes require(esm) stable, formalizing CommonJS and ESM compatibility across supported Node versions.