
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Command line tool, making it easier for developers to merge to master, when using the debitoor/teamcity-merge script
A command line tool making merge to master through teamcity-merge script easier for the developer. Before using this you should set up teamcity-merge
npm install -g tcmerge
> tcmerge "My awesome feature is done, it solves all kinds of problems"
In order for this to work, you have to be in a git repo. The branch you are currently on has to be an open pull request on github. And you have to have pushed your commits to the pull request branch on github.
tcmerge
$ git checkout master
$ git pull
$ git checkout -b merge-external-pull-request
Copy the commit id from the pull request in GitHub.
$ git cherry-pick -x {commit id}
Repeat as necessary.
$ git push --set-upstream origin merge-external-pull-request
$ hub pull-request -m "merge external pull request"
$ tcmerge "merge-external-pull-request Fixes #[EXTERNAL_PULL_REQUEST_NUMBER]"
That way the external PR will be closed when merge to master happens, and that merge commit will be linked to the external PR.
Also this module contais command prod
Requires HUB
brew install hub
> prod "hotfix-that-is-ready-go-prod"
notice that prod accepts only valid branch name that will be used as branch name, commit and PR
FAQs
Command line tool, making it easier for developers to merge to master, when using the debitoor/teamcity-merge script
The npm package tcmerge receives a total of 0 weekly downloads. As such, tcmerge popularity was classified as not popular.
We found that tcmerge demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 11 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.