
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
lint-prepush
Advanced tools
Run linters on committed files🔬
lint-prepush will run linters on the commited files while pushing the code to remote.
>=18.18.0
.npm install --save-dev lint-prepush
yarn
:yarn add --dev lint-prepush
Configure the following scripts in package.json to lint your committed files 🔧. You can also follow any of the cosmiconfig methods to configure lint-prepush.
pre-push git hook needs to be configured. Husky is a widely used package for managing git hooks.
{
+ "lint-prepush": {
+ "base": "main",
+ "tasks": {
+ "*.js": [
+ "eslint"
+ ]
+ }
+ }
}
The above scrips will lint the js files while pushing to git. It will terminate the process if there are any errors, otherwise, the changes will be pushed.
Tasks for a file group will by default run in linear order (eg. "*.js": [ "jest", "eslint"]
will run jest first, then after it's done run eslint).
If you'd like to run tasks for a file group concurrently instead (eg. jest and eslint in parallel), use the concurrent
property like so:
{
+ "lint-prepush": {
+ "tasks": {
+ "*.js": {
+ concurrent: [ "jest", "eslint" ]
+ }
+ }
+ }
}
By default when the tasks succeed, there is no output printed to the console. Sometimes you might need to show linter rules configured for warn
which should be displayed even if the tasks succeed. In order to achieve this, you can pass the config verbose: true
so that the task output is printed to the console when the tasks succeed.
"lint-prepush": {
"verbose": true,
"tasks": {
...
}
}
This package use SemVer for versioning. For the versions available, see the tags on this repository.
See also the list of contributors who participated in this project.
MIT @ Theena Dayalan
FAQs
Run linters on committed files in a Branch🔬
The npm package lint-prepush receives a total of 9,488 weekly downloads. As such, lint-prepush popularity was classified as popular.
We found that lint-prepush demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.