
Security News
OWASP 2025 Top 10 Adds Software Supply Chain Failures, Ranked Top Community Concern
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.
semantic-release-config-gitmoji
Advanced tools
shareable semantic-release configuration for gitmoji commit style
// .releaserc.js
module.exports = {
extends: ['semantic-release-config-gitmoji'],
};
use this in monorepo
// .releaserc.js
const { createConfig } = require('semantic-release-config-gitmoji/lib/createConfig');
const config = createConfig({ monorepo: true });
module.exports = config;
| name | type | optional | default | description |
|---|---|---|---|---|
| releaseRules | ReleaseRule[] | true | n/a | |
| changelogTitle | string | true | # Changelog | |
| changelogFile | string | true | CHANGELOG.md |
| name | type | optional | default | description |
|---|---|---|---|---|
| message | string | true | :bookmark: chore(release): ${nextRelease.gitTag} [skip ci]\n\n${nextRelease.notes} | The message for the release commit. See message. |
| gitAssets | false | string[] | ['CHANGELOG.md', 'package.json'] | Files to include in the release commit.Set to false to disable adding files to the release commit. See assets. |
| name | type | optional | default | description |
|---|---|---|---|---|
| enableGithub | boolean | true | true | 开启 github 插件 |
| name | type | optional | default | description |
|---|---|---|---|---|
| enableNPM | boolean | true | true | 开启 npm 插件 |
| npmPublish | boolean | true | n/a | Whether to publish the npm package to the registry. If false the package.json version will still be updated. false if the package.json private property is true, true otherwise |
| pkgRoot | string | true | n/a | Directory path to publish. default: . |
| tarballDir | string | false | true | n/a |
| monorepo | boolean | true | n/a | 如果是 Monorepo 仓库发布 npm 包,使用 "@semrel-extra/npm" 替代官方包 if using monorepo, use "@semrel-extra/npm" instead of the official package |
| name | type | optional | default | description |
|---|---|---|---|---|
| githubUrl | string | true | GH_URL or GITHUB_URL environment variable. | The GitHub Enterprise endpoint. |
| githubApiPathPrefix | string | true | GH_PREFIX or GITHUB_PREFIX environment variable. | The GitHub Enterprise API prefix. |
| githubAssets | string[] | true | - | An array of files to upload to the release. See assets. |
| proxy | string | true | HTTP_PROXY environment variable. | The proxy to use to access the GitHub API. See proxy. |
| successComment | string | true | :tada: This issue has been resolved in version ${nextRelease.version} :tada: | The release is available on GitHub release The assignees to add to the issue created when a release fails. |
MIT ® Arvin Xu
FAQs
a gitmoji commit style presets for semantic-release
The npm package semantic-release-config-gitmoji receives a total of 24,755 weekly downloads. As such, semantic-release-config-gitmoji popularity was classified as popular.
We found that semantic-release-config-gitmoji demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.