
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
$ npm install --global lope-cli
$ lope --help
Third-party NPM package scripts as simple CLIs
Usage:
$ lope <lope-package> <lope-script> [--lope-path path] [--* <*>]
Options:
--lope-package The package to run against (default: undefined)
--lope-path The path containing the package in node_modules (default: current directory or the
nearest ancestor node_modules directory)
--lope-script The script to run (default: undefined)
Examples:
$ lope lope-example test
$ lope lope-example echo --echo hello
PROTIP: Options prefixed with
lopewill be filtered and not passed to the NPM script
FAQs
Transform NPM package scripts into simple CLIs
The npm package lope-cli receives a total of 1 weekly downloads. As such, lope-cli popularity was classified as not popular.
We found that lope-cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.