
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Create .gitignore
file from any source such as Github or your local directory.
$ npm i -g giig
Fetch tpl
.gitignore template from registered source:
$ giig fetch [options] <tpl>
Options:
-s, --source [source]
: source name (default: github)-d, --dest [dest]
: project root (default: .gitignore)-h, --help
: output usage informationThe source must be registered before using. Except the github
is always available. See here for more info.
E.x: Download the Node
template from github
$ giig fetch Node
List all available .gitignore templates from src
source (default: github):
$ giig list [src]
E.x: Show all templates from github
$ giig list github
List all available sources:
$ giig src-list
Add/Update key
source info with list
and file
:
$ giig src-add <key> <list> [file]
Where:
list
: URL or Directory which contain list of templates. If list
is a url, it has to return a json file as Github Contents API.file
: The root path contains template file. Default is the value of list
.E.x 1: Add template source from ~/gitignore_tpl
folder with name igiig
$ giig src-add igiig "~/gitignore_tpl"
E.x 2: Add template source from https://github.com/dvcs/gitignore with name dvcs
$ giig src-add dvcs "https://api.github.com/repos/dvcs/gitignore/contents/templates" "https://raw.githubusercontent.com/dvcs/gitignore/master/templates"
Show key
source info:
$ giig src-show <key>
E.x: Show dvcs
source info
$ giig src-show dvcs
Remove key
source from source list:
$ giig src-del <key>
E.x: Remove dvcs
source
$ giig src-del dvcs
FAQs
Create .gitignore file from any source
We found that giig demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.