
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
github-label-fixer
Advanced tools
A command line utility to replace the default GitHub issue labels with ones Dave Sag finds more useful
An opinionated command line utility to replace the default GitHub issue labels with ones I find more useful
npm install -g github-label-fixer
then run labeller
, supply your GitHub personal token, ensuring that token gives the right to edit project labels, then supply your project owner name and the repository name, and it will blow away all the old issue labels and replace them with these:
{name: "bug", color: "ee0701"},
{name: "documentation", color: "1d76db"},
{name: "feature", color: "0052cc"},
{name: "help wanted", color: "b60205"},
{name: "please close", color: "076616"},
{name: "question", color: "cc317c"},
{name: "ready to merge", color: "0e8a10"},
{name: "tech debt", color: "5319e7"},
{name: "work in progress", color: "fbca04"}
I find the labels above more useful and I was sick of making the same changes by hand each time.
It's built for Node 6.9 or better. nvm install 6.9.4
to ensure you are running the latest supported version of node.
To run this in development mode
npm run dev
To run the unit tests
npm test
I am a fan of using the forked git-flow
process to manage contributions.
Please see the contributing notes for details.
It is working and core github access functions are unit tested.
1.0.0
— current version.0.0.9
— worked but without any unit testsFAQs
A command line utility to replace the default GitHub issue labels with ones Dave Sag finds more useful
We found that github-label-fixer demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.