Security News
New Python Packaging Proposal Aims to Solve Phantom Dependency Problem with SBOMs
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.
大家好, 我是秦始皇, 其实我并没有死, 我在西安有 100000 吨黄金, 今天肯德基疯狂星期四, 谁可以 V 我 50 元, 我明天直接带部队复活, 让你统领三军!
pip3 install crazy-thursday
或者
python3 -m pip install crazy-thursday
如果成功安装, 系统中便会存在一个名为 crazy-thursday
和一个名为 kfc
的命令. 直接调用 crazy-thursday
或 kfc
便会在控制台中随机地输出一段疯狂星期四文案.
你不需要贡献代码, 只需要创建 issue, 并且留下文案即可.
后台有一个定时任务, 定时收集本项目的所有 issue, 并汇总打包成 .whl
文件, 发布到 PyPI 上.
本项目采用 4 位版本号, 其格式为 <year>.<month>.<day>.<build>
, 其中:
<year>
为发布时间中的年份.<month>
为发布时间中的月份.<day>
为发布时间中的日期.<build>
为发布当天构建序号, 从 0
开始.比如版本 1926.8.16.3
含义为该版本是 1926 年 8 月 16 日构建的第 4 个版本.
本项利用 Github Actions 每天自动发布版本, 其工作原理如下图所示.
%%{init: {"theme": "base", "themeVariables": {"primaryColor": "#FFFFFF", "primaryBorderColor": "#000000"}}}%%
graph TD
A("☁️ https://github.com/zqmillet/crazy-thursday") -->|collect issues| B("📄 crazy_thursday/corpus.jsonl")
B -->|update version| C("📄 crazy_thursday/__init__.py")
C --> |commit & push| D("☁️ https://github.com/zqmillet/crazy-thursday")
D --> |build| E("📦 dist/crazy_thursday-*.whl")
E --> |publish| F("🌐 https://pypi.org/project/crazy-thursday")
定时任务的工作流程为:
scripts/update_curpus.py
脚本, 自动抓去本项目的所有 issue 并保存到 crazy_thursday/corpus.jsonl
文件中.crazy_thursday/__init__.py
文件中的版本号..whl
文件, 并发布到 PyPI 上.该定时任务每天会执行两次, 你提交的 issue 会出现在第二天的版本中.
FAQs
a cli tool to print crazy thursday article
We found that crazy-thursday demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.
Security News
Socket CEO Feross Aboukhadijeh discusses open source security challenges, including zero-day attacks and supply chain risks, on the Cyber Security Council podcast.
Security News
Research
Socket researchers uncover how threat actors weaponize Out-of-Band Application Security Testing (OAST) techniques across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.