
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
cz-customizable
Advanced tools
Commitizen customizable adapter following the conventional-changelog format.
This is a customizable Commitizen plugin. You can specify the commit types, scopes and override scopes for specific types.
Steps:
install commitizen case you don't have it: npm install -g commitizen
install the cz-customizable: npm install cz-customizable --save-dev
configure commitizen
to use cz-customizable
as plugin. There are a few ways to do this.
package.json
...
"config": {
"commitizen": {
"path": "node_modules/cz-customizable"
}
}
.cz.json
{
"path": "node_modules/cz-customizable"
}
Optionall step - Override the commit types and scopes:
.cz-config-EXAMPLE.js
to the root of your project..cz-config.js
and modify the options and scopes as you like.require(../../.cz-config)
in a nice way. If you know a better way please let me know. I definitelly want to learn how to do this better)
ln -nsf ../../.cz-config.js node_modules/cz-customizable/.cz-config.js
mklink /D node_modules\cz-customizable\.cz-config.js ..\..\.cz-config.js
you should commit your .cz-config.js
file to git.
node_modules/cz-customizable/.cz-config-EXAMPLE.js
From now on, instead of git commit
you type git cz
and let the tool do the work for you.
Hopefully this will help you to have consistent commit messages and have a fully automated deployemnt without any human intervention.
Related tools:
It prompts for conventional changelog standard.
Please feel free to send any suggestion.
FAQs
Commitizen customizable adapter following the conventional-changelog format.
The npm package cz-customizable receives a total of 47,808 weekly downloads. As such, cz-customizable popularity was classified as popular.
We found that cz-customizable demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.