
Research
Using Trusted Protocols Against You: Gmail as a C2 Mechanism
Socket uncovers malicious packages on PyPI using Gmail's SMTP protocol for command and control (C2) to exfiltrate data and execute commands.
JavaScript client for Git Awards (http://git-awards.com), discover you GitHub ranking
Discover your ranking on GitHub
JavaScript client for Git Awards (http://git-awards.com), discover you GitHub ranking
npm install git-awards // most likely, yarn instead
import { getUser, getRankForLanguage } from 'git-awards';
// Or with CommonJS:
// const { getUser, getRankForLanguage } = require('git-awards');
getUser('<your-username>')
.then(user => getRankForLanguage('<your-language>', user))
.then(console.log.bind(console));
For usage details see the documentation.
Here's a brief intro about what a developer must do in order to start developing the project further:
git clone https://github.com/blackxored/git-awards
cd git-awards
yarn
Build CommonJS modules, documentation and more, with:
yarn build
We use SemVer for versioning. In addition, it's automatic via semantic-release, and our commit convention.
For the versions available, see the Releases on this repository.
yarn test
We base our code style on AirBnB's style guide and we check with ESLint and automatically format our code with Prettier.
See the API reference in the documentation.
This project is licensed under the MIT License - see the license file for details.
If you're interested in contributing to this project in any form, please read our Contribution Guidelines.
We've adopted a Code of Conduct that we expect project participants to adhere to. Please read the full text so that you can understand what actions will and will not be tolerated.
Thanks goes to these people (emoji key):
Adrian Perez 💻 📖 🚇 ⚠️ | vincent daubry 🚇 |
---|
This project follows the all-contributors specification. Contributions of any kind welcome!
FAQs
JavaScript client for Git Awards (http://git-awards.com), discover you GitHub ranking
The npm package git-awards receives a total of 4 weekly downloads. As such, git-awards popularity was classified as not popular.
We found that git-awards demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious packages on PyPI using Gmail's SMTP protocol for command and control (C2) to exfiltrate data and execute commands.
Product
We redesigned Socket's first logged-in page to display rich and insightful visualizations about your repositories protected against supply chain threats.
Product
Automatically fix and test dependency updates with socket fix—a new CLI tool that turns CVE alerts into safe, automated upgrades.