
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
git-rev-sync
Advanced tools
The git-rev-sync npm package provides synchronous access to Git repository information, such as the current branch, commit hash, and other metadata. It is useful for embedding Git information into your application, such as for versioning or debugging purposes.
Get the current branch name
This feature allows you to retrieve the name of the current branch in the Git repository.
const git = require('git-rev-sync');
const branch = git.branch();
console.log(branch);
Get the current commit hash
This feature allows you to get the full hash of the current commit.
const git = require('git-rev-sync');
const commit = git.long();
console.log(commit);
Get the short commit hash
This feature provides the short version of the current commit hash.
const git = require('git-rev-sync');
const shortCommit = git.short();
console.log(shortCommit);
Get the commit message
This feature retrieves the commit message of the current commit.
const git = require('git-rev-sync');
const message = git.message();
console.log(message);
Get the commit date
This feature allows you to get the date of the current commit.
const git = require('git-rev-sync');
const date = git.date();
console.log(date);
The git-revision-webpack-plugin package provides similar functionality but is specifically designed to work with Webpack. It allows you to embed Git revision information into your Webpack build, which can be useful for versioning and cache busting.
The git-rev package offers similar functionalities to git-rev-sync but operates asynchronously. It provides methods to get the current branch, commit hash, and other Git metadata, but uses callbacks or promises instead of synchronous calls.
The simple-git package is a more comprehensive Git library for Node.js that provides both synchronous and asynchronous methods to interact with a Git repository. It offers a wider range of Git operations compared to git-rev-sync, making it more versatile for complex Git interactions.
Synchronously get the current git commit hash, tag or branch
var git = require('git-rev-sync');
console.log(git.short());
// 75bf4ee
console.log(git.long());
// 75bf4eea9aa1a7fd6505d0d0aa43105feafa92ef
console.log(git.branch());
// master
console.log(git.tag());
// 0.1.0
console.log(git.log());
// [
// [
// '75bf4eea9aa1a7fd6505d0d0aa43105feafa92ef',
// 'update pjson to include sync exec',
// '17 minutes ago',
// 'kurttheviking'
// ],
// [
// '143120ac3ecc07aeae1462b372bb2033aa20c3ee',
// 'Merge pull request #6 from shtylman/patch-1',
// '1 year, 2 months ago',
// 'Thomas Blobaum'
// ],
// ...
// ]
You can also run these examples via: npm run examples
npm install git-rev-sync --save
var git = require('git-rev-sync');
return the git log of process.cwd()
as an array; each array contains the long commit hash, commit message, fuzzy commit time, and user
return the result of git rev-parse --short HEAD
return the result of git rev-parse HEAD
return the current tag
return the current branch
Not tested outside of a *nix system. See the execSync module notes on this topic.
FAQs
Synchronously get the current git commit hash, tag, or branch
The npm package git-rev-sync receives a total of 270,841 weekly downloads. As such, git-rev-sync popularity was classified as popular.
We found that git-rev-sync demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.