Security News
GitHub Removes Malicious Pull Requests Targeting Open Source Repositories
GitHub removed 27 malicious pull requests attempting to inject harmful code across multiple open source repositories, in another round of low-effort attacks.
download-git-repo
Advanced tools
Download and extract a git repository (GitHub, GitLab, Bitbucket) from node.
Download and extract a git repository (GitHub, GitLab, Bitbucket) from node.
$ npm install download-git-repo
Download a git repository
to a destination
folder with options
, and callback
.
The shorthand repository string to download the repository from:
github:owner/name
or simply owner/name
gitlab:owner/name
bitbucket:owner/name
The repository
parameter defaults to the master
branch, but you can specify a branch or tag as a URL fragment like owner/name#my-branch
.
In addition to specifying the type of where to download, you can also specify a custom origin like gitlab:custom.com:owner/name
.
Custom origin will default to https
or git@
for http and clone downloads respectively, unless protocol is specified.
Feel free to submit an issue or pull request for additional origin options.
In addition to having the shorthand for supported git hosts, you can also hit a repository directly with:
direct:url
This will bypass the shorthand normalizer and pass url
directly.
If using direct
without clone, you must pass the full url to the zip file, including paths to branches if needed.
If using direct
with clone, you must pass the full url to the git repo and you can specify a branch like direct:url#my-branch
.
The file path to download the repository to.
An optional options object parameter with download options. Options include:
clone
- boolean default false
- If true use git clone
instead of an http download. While this can be a bit slower, it does allow private repositories to be used if the appropriate SSH keys are setup.proxy
, headers
, filter
, etc.) will be passed down accordingly and may override defaults
The callback function as function (err)
.
Using http download from Github repository at master.
download('flipxfx/download-git-repo-fixture', 'test/tmp', function (err) {
console.log(err ? 'Error' : 'Success')
})
Using git clone from Bitbucket repository at my-branch.
download('bitbucket:flipxfx/download-git-repo-fixture#my-branch', 'test/tmp', { clone: true }, function (err) {
console.log(err ? 'Error' : 'Success')
})
Using http download from GitLab repository with custom origin and token.
download('gitlab:mygitlab.com:flipxfx/download-git-repo-fixture#my-branch', 'test/tmp', { headers: { 'PRIVATE-TOKEN': '1234' } } function (err) {
console.log(err ? 'Error' : 'Success')
})
Using git clone from GitLab repository with custom origin and protocol.
Note that the repository type (github
, gitlab
etc.) is not required if cloning from a custom origin.
download('https://mygitlab.com:flipxfx/download-git-repo-fixture#my-branch', 'test/tmp', { clone: true }, function (err) {
console.log(err ? 'Error' : 'Success')
})
Using http download from direct url.
download('direct:https://gitlab.com/flipxfx/download-git-repo-fixture/repository/archive.zip', 'test/tmp', function (err) {
console.log(err ? 'Error' : 'Success')
})
Using git clone from direct url at master.
download('direct:https://gitlab.com/flipxfx/download-git-repo-fixture.git', 'test/tmp', { clone: true }, function (err) {
console.log(err ? 'Error' : 'Success')
})
Using git clone from direct url at my-branch.
download('direct:https://gitlab.com/flipxfx/download-git-repo-fixture.git#my-branch', 'test/tmp', { clone: true }, function (err) {
console.log(err ? 'Error' : 'Success')
})
MIT
FAQs
Download and extract a git repository (GitHub, GitLab, Bitbucket) from node.
The npm package download-git-repo receives a total of 15,042 weekly downloads. As such, download-git-repo popularity was classified as popular.
We found that download-git-repo demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
GitHub removed 27 malicious pull requests attempting to inject harmful code across multiple open source repositories, in another round of low-effort attacks.
Security News
RubyGems.org has added a new "maintainer" role that allows for publishing new versions of gems. This new permission type is aimed at improving security for gem owners and the service overall.
Security News
Node.js will be enforcing stricter semver-major PR policies a month before major releases to enhance stability and ensure reliable release candidates.