
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
gitflow-semver
Advanced tools
Git extensions to automatically create release branches with SemVer names
Install git and git-flow with brew:
$ brew install git
$ brew install git-flow
Then install using npm:
$ npm install -g gitflow-semver
Install git from here. Make sure you choose the scary sounding option about what to add to your PATH.
Clone this repository with git clone --recursive
Install git-flow and a shim for git-release with our installer:
> install.bat
Then install using npm:
> npm install -g gitflow-semver
$ git release # to create a new release
$ git release --init # to initialize the repo
The actual work of creating branches etc is carried out by Git Flow. Patch releases are implemented as Git Flow hotfixes.
Note: when fixing a bug and doing a patch release, you currently have to start the patch before you do the bug fix, because of how git-flow hotfixes work.
FAQs
Git extensions to automatically create release branches with SemVer names
The npm package gitflow-semver receives a total of 13 weekly downloads. As such, gitflow-semver popularity was classified as not popular.
We found that gitflow-semver demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.