
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
git-push-server
Advanced tools
This node module makes it easy to build an HTTP stateless git-push server, to build stuff like Heroku or GitBook.io without keeping the repositories content.
$ npm install git-push-server
var GitPush = require("git-push-server");
var express = require("express");
var path = require("path");
// Create the http application
var app = express();
// Create the git-push server
var git = new GitPush();
// Create a router for the git-push server
var router = express.Router();
// Start the git server on the router
git.start(router);
// Bind the router to the app
app.use('/:author/:repo.git', function(req, res, next) {
// Needed to identify the repository
req.repoId = [req.params.author, req.params.repo].join("/");
next();
});
app.use('/:author/:repo.git', router);
// Start the http server
var server = app.listen(3000, function() {
console.log('Listening on port %d', server.address().port);
});
You can now run from a git repository:
$ git push http://localhost:3000/test/test.git master
If you need to run an operation on the folder resulting from the push, you need to override push. For async operaiton, this method can return a promise.
git.push = function(pushInfos) {
// pushInfos.repoId
// pushInfos.auth.username
// pushInfos.auth.password
// pushInfos.content
// pushInfos.bare
// do some build or deployment operation
};
You need to override authenticate to make authentication work. It should return a boolean or a promise for async authentication.
git.authenticate = function(infos) {
// infos.repoId -> repository id set with in req.repoID
// infos.username
// infos.password
return doSomethingWithDatabase(infos.username, infos.password, infos.repoId);
};
var git = new GitPush(options);
options.debug: enable log messages (default false)
options.root: root directory for the repositories (default os.tmpdir)
FAQs
Make it easy to build an HTTP stateless git-push server
We found that git-push-server demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.