Security News
RubyGems.org Adds New Maintainer Role
RubyGems.org has added a new "maintainer" role that allows for publishing new versions of gems. This new permission type is aimed at improving security for gem owners and the service overall.
This is a publishing tool for Node.js projects hosted in a git repository.
It makes use of the publishConfig
section
of a project's package.json
.
publishConfig
In your project's package.json
,
you can optionally include a publishConfig
section.
Below is an example.
"publishConfig": {
"registry": "http://some-registry.dev",
"license": {
"exclude": [
"lib"
]
}
}
publishConfig.registry
Specify a custom registry for use
in the npm install
and npm publish
commands.
This is a native
npm feature.
publishConfig.license.exclude
Specify an array of directories to ignore
for the npub prep
command.
prep
commandnpub prep
LICENSE
file exists in the current directory, abort*.{js,coffee}
files recursively in the current directory, excluding those in publishConfig.license.exclude
(and ./node_modules
)publish
commandnpub publish <version>
Options:
-t/--test command
- alternate test suite command. default: npm test
<version>
- 1.2.3
; or, for auto increments: patch
, minor
, major
npub verify
npub prep
npub verify
package.json
update) with message "v1.2.3"
v1.2.3
"about to publish"
; otherwise abortgit push
git push --tags
npm publish
verify
commandnpub verify
git status
is clean, exit with 0
; otherwise exit with a status of 2
FAQs
publishing tool for your node projects hosted on github
The npm package npub receives a total of 11 weekly downloads. As such, npub popularity was classified as not popular.
We found that npub demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
RubyGems.org has added a new "maintainer" role that allows for publishing new versions of gems. This new permission type is aimed at improving security for gem owners and the service overall.
Security News
Node.js will be enforcing stricter semver-major PR policies a month before major releases to enhance stability and ensure reliable release candidates.
Security News
Research
Socket's threat research team has detected five malicious npm packages targeting Roblox developers, deploying malware to steal credentials and personal data.