
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Create releases in GitHub using release notes from a Jira version.
npm install -g greleaser
export JIRA_ORGNAME='myjiraorg'
export JIRA_USERNAME='me@email.com'
export JIRA_PASSWORD='jirapassowrd'
export GITHUB_USERNAME='me'
export GITHUB_PASSWORD='githubpassword'
export GITHUB_ORG_NAME='mygithuborg'
Note that if you use 2FA on GitHub, you'll need to use a personal access with the repo
scope in place of your GitHub password.
10015
.greleaser -p <projectId> -v <versionNumber> -g <gitHubRepo>
to create a release in GitHub using the release notes from Jira.You specify the GitHub project name on the command line with the -g
argument.
By default, the master
branch is tagged, but you can choose a different commit with the -c
command line argument.
The tag name will be the version number pulled from the Jira version name. For example, if your Jira version is named v1.0
, then the GitHub tag will be named v1.0
. You can override the tag name with the -t
option.
You can name your Jira releases however you like, but Releaser is going to split the name on a space and use the last result in that array.
For example:
v1.0
in Jira becomes v1.0
in GitHub
API v1.0
becomes v1.0
in GitHub
v1.0 API
becaomse API
in GitHub
If this doesn't suit you, you can pass different release and tag names with the -r
and -t
options respectively.
greleaser -h
Release notes are not available in the Jira Cloud REST API.
my-github-project
.greleaser -p 10003 -v 10001 -g my-github-project
v1.0
in project 10003 to my-github-project
, tag commit dca12345
, tag the commit as version1
and call the release My Release
.greleaser -p 10003 -v 10001 -g my-github-project -c dca12345 -t version1 -r "My Release"
MIT
FAQs
Create releases in GitHub using release notes from a Jira version.
The npm package greleaser receives a total of 1 weekly downloads. As such, greleaser popularity was classified as not popular.
We found that greleaser demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.