
Security News
Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline, Forces Certificate Rotation
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.
mol-commitlint-config
Advanced tools
commitlint configuration for mol-conventional-changelog
# Install commitlint cli and mol commitlint config
npm install --save-dev mol-commitlint-config @commitlint/cli
# Configure commitlint to use mol commitlint config
echo "module.exports = {extends: ['./node_modules/mol-commitlint-config']}" > commitlint.config.js
or in the package.json
{
"commitlint": {
"extends": [
"./node_modules/mol-commitlint-config"
]
}
}
To lint commits before they are created you can use the 'commitmsg' hook as described here
{
"scripts": {
"commitmsg": "commitlint -E GIT_PARAMS"
}
}
Detailed Setup instructions
{{type}}: {{subject}}
<BLANK LINE>
{{body}}
<BLANK LINE>
{{breaking changes}}
<BLANK LINE>
{{footer}}
The header is the only mandatory part of the commit message.
The first line (type + subject) is limited to 50 characters [enforced]
Any other line should be limited to 72 character [automatic wrapping]
This allows the message to be easier to read on GitHub as well as in various git tools.
Must be one of the following:
feat: A new feature.fix: A bug fix.docs: Documentation only changes.style: Markup-only changes (white-space, formatting, missing semi-colons, etc).refactor: A code change that neither fixes a bug or adds a feature.perf: A code change that improves performance.test: Adding or updating tests.chore: Build process or auxiliary tool changes.ci: CI related changes.The subject contains succinct description of the change:
Just as in the subject, use the imperative, present tense: "change" not "changed" nor "changes". The body should include the motivation for the change and contrast this with previous behavior.
Select the packages the commit affected.
Breaking Changes must start with the words BREAKING CHANGE: .
The footer is the place to reference any tasks related to this commit.
FAQs
Shareable commitlint config enforcing MOL conventional commits
The npm package mol-commitlint-config receives a total of 18 weekly downloads. As such, mol-commitlint-config popularity was classified as not popular.
We found that mol-commitlint-config demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.

Security News
Open source is under attack because of how much value it creates. It has been the foundation of every major software innovation for the last three decades. This is not the time to walk away from it.

Security News
Socket CEO Feross Aboukhadijeh breaks down how North Korea hijacked Axios and what it means for the future of software supply chain security.