Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
metalpress
Advanced tools
Create a blog easily with Metalsmith.
A wrapper of Metalsmith plugins for quickly creating a blog with Metalsmith.
$ npm install metalpress --save
metalpress works from a specific directory structure. It contains a templates
and src
directory. Within the src directory it will load data from data
as yaml
or json
files. You can create folders for collections and use markdown files for pages. You should store all assets in assets
.
For templating, metalpress uses liquid. You can learn more about the syntax here.
Here's an example structure:
├── package.json
├── src
│ ├── data
│ ├── site.yaml
│ ├── projects.json
│ ├── assets
│ ├── sass
│ ├── img
│ ├── fonts
│ ├── js
│ ├── index.js
│ ├── index.md
│ ├── pages
│ ├── about.md
│ └── posts
│ ├── 2016-08-25-how-to-use-metalpress.md
├── templates
│ ├── _includes
│ ├── header.liquid
│ ├── footer.liquid
│ └── _layouts
│ ├── home.liquid
To get started with metalpress, you can use the API or CLI.
metalpress taks a config object and callback. It will process the files in the config, build the site, and return a metalsmith instance. The callback will contain any errors and the file mappings.
import metalpress from 'metalpress';
import config from './metalpress.config';
const m = metalpress(config, (err, files) => {
console.log('New site build completed.');
});
npm install metalpress-cli -g
Prompts a series of questions and creates a new
.metalpress
config.
metalpress init
Serve the project on automatically assigned browser-sync port. (default: http://localhost:3000)
metalpress serve
To deploy your site, you'll need to have your aws.json
set up. It includes:
{
"key":"AWS_ACCESS_KEY_HERE",
"secret":"AWS_SECRET_KEY_HERE",
"stagingBucket":"staging.example.com",
"productionBucket":"example.com"
}
Deploy a
dist
and deployed to AWS S3.
Staging
metalpress deploy
Production
metalpress deploy -p
By default, metalpress uses a webpack configuration for both staging and production environments. Within your config, you can specify jquery: true
for included support jquery.
If you need to do so, you can override webpack with a custom config. For example, you can use the following options in your .metalpress config. You can add only the parameters you need which will be extended into the defaults, or override the entire file as needed.
{
"webpack": {
"dev": "./webpack.config.js",
"prod": "./webpack.prod.config.js"
}
}
For Questions, Issues, PRs please refer to @cameronroe
FAQs
Create a blog easily with Metalsmith.
The npm package metalpress receives a total of 3 weekly downloads. As such, metalpress popularity was classified as not popular.
We found that metalpress demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.