Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Stop wasting time syncing and updating your project's README and Package Files!
Stop wasting time syncing and updating your project's README and Package Files!
Here's some of the things it can do:
package.json
bower.json
component.json
jquery.json
README
CONTRIBUTING
LICENSE
BACKERS
HISTORY
npm install --global projectz
projectz
Once installed locally, you can compile your project using projectz by running the following in your terminal:
node ./node_modules/.bin/projectz compile
To make projectz more automatic, we recommended adding the direct command above to your build tool.
If you don't use a build tool, but do use npm, then you can add the following to your project's package.json
file:
{
"scripts": {
"compile": "node ./node_modules/.bin/projectz compile",
"posttest": "node ./node_modules/.bin/projectz compile"
}
}
The compile
script here lets you use npm run-script compile
to compile your project with projectz.
The posttest
script here automatically compiles your project with projectz after your tests have successfully completed, providing you use npm test
to run your tests. This is a great place to put projectz as projectz only updates meta documents so won't affect your test, and will always run before a publish.
Projectz helps you maintain the following data files:
package.json
bower.json
component.json
jquery.json
It does this by reading them, combining their data in memory, and then outputting the appropriate fields and over-rides for each file.
Each file can serve as the master meta data file, however you can also define a projectz.cson
CSON file that you can use if you'd like to have the benefit of comments, optional commas, multiline strings, etc for your primary meta data file.
The special fields are as so:
{
# Project's human readable name
title: "Projectz",
# Project name
name: "projectz",
# Project's Website URL
homepage: "https://github.com/bevry/projectz",
# Project's demo URL
# If this is missing, and `homepage` is set, we set it to the `homepage` value
demo: "https://github.com/bevry/projectz",
# Project description
description: "Stop wasting time syncing and updating your project's README and Package Files!",
# Project's SPDX License
# Uses https://www.npmjs.com/packages/spdx for parsing
license: "MIT",
# Whether the project can run on the client-side in web browsers
# If this is missing, and the component or bower package files exist, then this becomes `true`
browsers: true,
# Project's author details
# Can be an array or CSV string
author: "2013+ Bevry Pty Ltd <us@bevry.me> (http://bevry.me)",
# Maintainers
maintainers: [
"Benjamin Lupton (b@lupton.cc) (http://balupton.com)"
],
# Sponsors
sponsors: [
"Benjamin Lupton (b@lupton.cc) (http://balupton.com)"
],
# Contributors
# Automatically combined with the contributors from the GitHub Repository API
contributors: [
"Benjamin Lupton (b@lupton.cc) (http://balupton.com)"
],
# Project's repository details
# If this is missing, and `homepage` is a GitHub URL, this determined automatically
repository: {
type: "git",
url: "https://github.com/bevry/projectz.git"
},
# Project's issue tracker
# If this is missing, and `repository` is a GitHub repository, this determined automatically
bugs: {
url: "https://github.com/bevry/projectz/issues"
},
# Project's badges for use in the readme files
# Uses https://www.npmjs.com/packages/badges for parsing and rendering, see for usage
badges: {
list: []
config: {}
}
}
Projectz helps you maintain the following readme files:
README.md
CONTRIBUTING.md
LICENSE.md
BACKERS.md
HISTORY.md
It does this by reading them, and replacing comment tags with the appropriate data.
The following comment tags are supported:
<!-- TITLE -->
— outputs the package's title
field<!-- BADGES -->
— outputs the badges you have enabled from your package's badges
field<!-- DESCRIPTION -->
— outputs the package's description
field<!-- INSTALL -->
— outputs the package's installation instructions<!-- HISTORY -->
— outputs a link to the HISTORY
file if it exists, otherwise if it is a Github repository, outputs a link to the releases page<!-- CONTRIBUTE -->
— outputs a link to the CONTRIBUTE
file if it exists<!-- BACKERS -->
— outputs the information from the sponsors
field, as well as any funding badges<!-- LICENSE -->
— outputs a summary of the license informationAs well as these comment tags for updating entire files:
<!-- LICENSEFILE -->
— outputs the complete license information<!-- BACKERSFILE -->
— same as <!-- BACKERS -->
but made for an individual file insteadAs an example, here is a a basic README.md
file:
<!-- TITLE -->
<!-- BADGES -->
<!-- DESCRIPTION -->
<!-- INSTALL -->
## Usage
Usage instructions go here
<!-- HISTORY -->
<!-- CONTRIBUTE -->
<!-- BACKERS -->
<!-- LICENSE -->
Discover the release history by heading on over to the HISTORY.md
file.
Discover how you can contribute by heading on over to the CONTRIBUTING.md
file.
These amazing people are maintaining this project:
No sponsors yet! Will you be the first?
These amazing people have contributed code to this project:
Discover how you can contribute by heading on over to the CONTRIBUTING.md
file.
Unless stated otherwise all works are:
and licensed under:
FAQs
Stop wasting time syncing and updating your project's README and Package Files!
The npm package metabuild receives a total of 14 weekly downloads. As such, metabuild popularity was classified as not popular.
We found that metabuild demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.