
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Github Pull Request notification utility
Majordome is a simple cli program to generate notifications if you have open/outstanding pull-request reviews on Github. It can also be used to display the pull-requests on the command line.
The notifications are linked to the search in the format:
type:pr is:open review:required review-requested:<username>
Installing:
npm install -g majordome
Setup:
~/.github
~/.github
majordome check
Check for outstanding PR reviews, if there are more than 0 a notification will be triggered.
majordome list
List all the outstanding PR reviews. The will be grouped by repository and the title along with the age of the PR will be displayed. Depending on the terminal, these can also be used as links - typically holding Command (OSX) whilst clicking will trigger the link to open (Terminal.app, iTerm, etc..)
FAQs
Github Pull Request notificaiton bot
The npm package majordome receives a total of 0 weekly downloads. As such, majordome popularity was classified as not popular.
We found that majordome demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.