
Research
wget to Wipeout: Malicious Go Modules Fetch Destructive Payload
Socket's research uncovers three dangerous Go modules that contain obfuscated disk-wiping malware, threatening complete data loss.
The basic structure and files for creating a DevWatch blog. Pulled down by dw-cli.
You can have Travis deploy your module to npm when a build passes and a tag is present.
First you have to generate a token from npm either on the site or by running the following by a signed in user.
npm token create
Second you must add the following variables to your travis ci project.
NPM_EMAIL
NPM_TOKEN
Finally, after you have commited your changes and you want to deploy your module run the following commands in your terminal
# this will bump up the version in your package.json
npm version [patch] || [minor] || [major]
# this pushes your master and adds a git tag
git push origin master --tag
Travis will run your build and if successful push your module to the npm registry with appropriate version bump.
FAQs
A Node powered static site generator
We found that dw-starter demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket's research uncovers three dangerous Go modules that contain obfuscated disk-wiping malware, threatening complete data loss.
Research
Socket uncovers malicious packages on PyPI using Gmail's SMTP protocol for command and control (C2) to exfiltrate data and execute commands.
Product
We redesigned Socket's first logged-in page to display rich and insightful visualizations about your repositories protected against supply chain threats.