
Research
SANDWORM_MODE: Shai-Hulud-Style npm Worm Hijacks CI Workflows and Poisons AI Toolchains
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.
bombhtml
Advanced tools
<bomb>HTML</bomb>simple html/css templating / static site generator system written in python
Keep your html DRY! This tool helps to bomb away useless repetitions.
things may break or will not work properly. Things may break, so consider making a backup of your work the first time trying to use this.
NOTE: you might want to make this in a virtual environment.
$ pip install -U wheel
$ pip install -U bombhtml
This guide assumes you have already a virtual enviroment set up and activated.
You can for example us emailbomb/bombdotemail to test your changes, as the repository uses this build system.
in the config file set
build.debug_print = True
$ python3 -m build
$ pip install --force-reinstall dist/bombhtml-v.v.v-py3-none-any.whl
replace v.v.v with the actual version number. The version number can be found in ./bombhtml/__init__.py
$ python3 -m twine upload --repository testpypi dist/*
$ test test test
not available yet
Double licensed as GPLv3+ and MIT (before version 0.4.0 only as GPLv3+)
FAQs
simple html/css templating / static site generator system written in python
We found that bombhtml demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.

Company News
Socket is proud to join the OpenJS Foundation as a Silver Member, deepening our commitment to the long-term health and security of the JavaScript ecosystem.

Security News
npm now links to Socket's security analysis on every package page. Here's what you'll find when you click through.