
Research
npm Malware Targets Telegram Bot Developers with Persistent SSH Backdoors
Malicious npm packages posing as Telegram bot libraries install SSH backdoors and exfiltrate data from Linux developer machines.
get-repo-images
Advanced tools
An extremely fast repository crawler to find images across multiple repos
As Shopify has scaled, our usage of illustrations in code has become fragmented across 6000+ repositories. We recently updated our illustration style and finding the illustrations, prioritising them, removing or updating them across our codebase was a challenge. We hope that get-repo-images
will be useful for anyone maintaining images at scale.
Status | Owner | Help |
---|---|---|
Experimental | @polaris-team | New issue |
Start a website at at http://localhost:3000 to browse, sort and filter images from alex-page/alexpage.com.au
$ npx get-repo-images -repo alex-page/alexpage.com.au
Create the files for a Next.js website into the ./repo-images-site
directory
$ npx get-repo-images -build -repo alex-page/alexpage.com.au
Note: If you want to run the website you can run
cd repo-images-site && npm i && npm run dev
Generate a JSON file with results to ./images.json
$ npx get-repo-images -json -repo alex-page/alexpage.com.au
Private repositories
Add a personal access token for private repositories. Replace TOKEN
with your token.
$ npx get-repo-images -repo alex-page/alexpage.com.au -token TOKEN
Advanced usage
To get the images from multiple repositories, specific image extensions, minimum image sizes you can add more options to the repos.config.json
:
$ npx get-repo-images -settings get-repo-images.json
// get-repo-images.json
{
"repos": [
{
"repo": "shopify/android",
"minSize": 1000,
"extensions": ["webp"],
"usageMatchers": ["drawable"],
"usageNoExtension": true
},
{"repo": "alex-page/harmonograph.art"},
]
}
get-repo-images is built using the following technologies:
FAQs
An extremely fast repository crawler to find images across multiple repos
We found that get-repo-images demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Malicious npm packages posing as Telegram bot libraries install SSH backdoors and exfiltrate data from Linux developer machines.
Security News
pip, PDM, pip-audit, and the packaging library are already adding support for Python’s new lock file format.
Product
Socket's Go support is now generally available, bringing automatic scanning and deep code analysis to all users with Go projects.