Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
create-github-actions-setup-for-ember-addon
Advanced tools
Creates GitHub Actions for Ember Addon with NPM init / yarn create command.
The script analyzes an existing TravisCI configuration and tries to migrate it over to GitHub Actions.
This is early alpha software. Use with care and double check the generated GitHub Actions workflow.
# in a yarn repo
yarn create github-actions-setup-for-ember-addon
# in an npm repo
npm init github-actions-setup-for-ember-addon
Merge requests are very much appreciated. Parts that could be improved are:
The script is written in TypeScript. Therefore development branch can not be directly executed unless using ts-node.
yarn compile
/path/to/script/bin/create-github-actions-setup-for-ember-addon
Tests are written with jest using Snapshots Testing. A test ist autogenerated for every file in tests/fixtures
. Please double check that the generated snapshot is correct when adding an additional file. Snapshot tests are passing if no snapshot exists yet.
The tests are executed by yarn test
.
This project is licensed under the MIT License.
FAQs
Setup GitHub Actions for an Ember Addon
The npm package create-github-actions-setup-for-ember-addon receives a total of 0 weekly downloads. As such, create-github-actions-setup-for-ember-addon popularity was classified as not popular.
We found that create-github-actions-setup-for-ember-addon demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.