
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
git-heatmap
Advanced tools
Display file/author heatmap in the console. e.g ``` ┌───────┬───────────────────────────────────────┬────────┬────────┬──────────────────────────────────────────────────────────────────┐ │ Index │ Entry │ # file │ # line │
Display file/author heatmap in the console. e.g
┌───────┬───────────────────────────────────────┬────────┬────────┬──────────────────────────────────────────────────────────────────┐
│ Index │ Entry │ # file │ # line │ Wed Aug 31 2022 Tue Nov 01 2022 │
├───────┼───────────────────────────────────────┼────────┼────────┼──────────────────────────────────────────────────────────────────┤
│ 1 │ ...MyTestProject/Code/TestFile1.ts │ 129 │ 494 │ ▨▨▨ ▨▨▩▨▨▩ ▨▩▩▨▨ ▨▩▨▨ ▨▨▨▨ ▨▨ ▨▨▩▨ ▨▨▩ ▨▨▨▨▨ │
│ 2 │ ...MyTestProject/Code/TestFile2.ts │ 70 │ 268 │ ▨ ▨▨ ▨ ▨▩▨▨ ▨▨▩ ▨ ▨▨▩▨ ▨ ▨▨ ▩▩▩ ▨ ▨▩▩ ▩▨▨ │
└───────┴───────────────────────────────────────┴────────┴────────┴──────────────────────────────────────────────────────────────────┘
Options:
-n, --numCommits <number> number of commits to check (default: "1000")
-s, --startDate <date> start date of the commits to filter (e.g. 2022-01-01 default: "")
-i, --ignore <filter> ignore files types (glob patterns separated by space, default: "")
-k, --topK <number> Top k result to return (default: "20")
-w, --weight <number> the weight factor of line change (default: "0.5")
-e, --email <email> filter by author email
-c, --commit <sha> filter by commit sha hash
-h, --help display help for command
To install:
npm i git-heatmap -g
To use this tool, cd to a git directory
git-heatmap
Examples with filters
# Filter out all .json and .lock files
git-heatmap -i "**/*.json **/*.lock"
# Show author heatmap
git-heatmap -a
# Filter commits since 2022-01-01
git-heatmap -s 2022-01-01
FAQs
Display file/author heatmap in the console. e.g ``` ┌───────┬───────────────────────────────────────┬────────┬────────┬──────────────────────────────────────────────────────────────────┐ │ Index │ Entry │ # file │ # line │
The npm package git-heatmap receives a total of 4 weekly downloads. As such, git-heatmap popularity was classified as not popular.
We found that git-heatmap demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.