Security News
New Python Packaging Proposal Aims to Solve Phantom Dependency Problem with SBOMs
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.
[![Travis Status][travis-badge]][travis-project] [![Shippable Status][shippable-badge]][shippable-project]
I have created this script to help me open issues automatically in appropriate repositories after reading the details from a so called PM Issue
.
The supported syntax for the PM Issue
is like this
- [ ] **1** Task 1 title. Task 1 Description
- [ ] **2** [repo1] Task 2 title. Task 2 Description
- [ ] **3** [repo2] Task 3 title. Task 3 Description
...
npm install -g github-io
githubIO (PM Issue URL) (Default repo to open issues in, if not provided in the pm issue description)
For the following sample PM Issue: https://github.com/orgName/pmRepoName/issues/1234
### Summary
Create a `TODO` application
### Description
The application must support adding, updating and deleting a TODO.
### Scenarios
- [ ] **1** add `todo/new` POST route
- [ ] **2** add `todo/:id` GET route
- [ ] **3** add `todo/:id` PUT route
- [ ] **4** add `todo/:id` DELETE route
- [ ] **5** add `todo` GET route. Add support for `sort`, `isEnabled` & `assignee` query parameter
- [ ] **6** [wwwRepo] Add the view for TODO
- [ ] **7** [docsRepo] Update the docs for TODO
And following Usage
github-io https://github.com/orgName/pmRepoName/issues/1234 testApiRepo
The value testApiRepo
is taken from the default repo value passed to the script
DEV 1234.1 add
todo/new POST route
Description: Link to PM IssueDEV 1234.2 add
todo/:id GET route
Description: Link to PM IssueDEV 1234.3 add
todo/:id PUT route
Description: Link to PM IssueDEV 1234.4 add
todo/:id DELETE route
Description: Link to PM IssueDEV 1234.5 add
todo GET route.
Description Link to PM Issue, Add support for sort, isEnabled & assignee query parameter
The value wwwRepo
from the description has overridden the default repo value
DEV 1234.6 [www] Add the view for TODO
The value docsRepo
from the description has overridden the default repo value
DEV 1234.7 [docs] Update the docs for TODO
FAQs
[![Travis Status][travis-badge]][travis-project] [![Shippable Status][shippable-badge]][shippable-project]
The npm package github-io receives a total of 1 weekly downloads. As such, github-io popularity was classified as not popular.
We found that github-io demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.
Security News
Socket CEO Feross Aboukhadijeh discusses open source security challenges, including zero-day attacks and supply chain risks, on the Cyber Security Council podcast.
Security News
Research
Socket researchers uncover how threat actors weaponize Out-of-Band Application Security Testing (OAST) techniques across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.