
Research
SANDWORM_MODE: Shai-Hulud-Style npm Worm Hijacks CI Workflows and Poisons AI Toolchains
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.
taco-git-push-deploy
Advanced tools
git push deploy with taco
npm install -g taco-git-push-deploy
First go into your application that you want to deploy using git push
cd my-app
Make sure this app has a package.json that contains a name field. Then run
# substitute maf@mafintosh.com with an ssh user/host you want to setup deployment to
taco-git-push-deploy maf@mafintosh.com
This will open your editor with a file that looks like this one
#!/bin/bash
# setup your taco pipeline
# make sure git, taco-build, taco-mon etc is installed on your server
git archive --format=tar master | taco-build "npm install" | taco-mon deploy ~
This is the script that will be running on the server when you git push to it.
If you wan't to use a different build command than npm install etc you should edit it here.
When you save and close this script file in your editor taco-git-push-deploy will login to
your server, create a bare git repo, add your script as a post-receive hook and and the repo
as a remote called deploy in your local repo
Now all you need to do to deploy your app is
git push deploy master
MIT
FAQs
git push deploy with taco
We found that taco-git-push-deploy demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.

Company News
Socket is proud to join the OpenJS Foundation as a Silver Member, deepening our commitment to the long-term health and security of the JavaScript ecosystem.

Security News
npm now links to Socket's security analysis on every package page. Here's what you'll find when you click through.