
Security News
Crates.io Users Targeted by Phishing Emails
The Rust Security Response WG is warning of phishing emails from rustfoundation.dev targeting crates.io users.
This repository contains the following molecule plugins:
Installing molecule-plugins
does not install dependencies specific to each,
plugin. To install these you need to install the extras for each plugin, like
pip3 install 'molecule-plugins[azure]'
.
Before installing these plugins be sure that you uninstall their old standalone
packages, like pip3 uninstall molecule-azure
. If you fail to do so, you will
end-up with a broken setup, as multiple plugins will have the same entry points,
registered.
The release.yml
workflow generates the wheel and uploads the release to PyPI.
Here are the steps you need to kick that process off:
Use a calver tag in the format vYY.MM.DD.
Create a new tag and push it to the repo.
git tag -s <NEW_VERSION> -m "Tag message"
git push --tags upstream
It is possible to create lightweight tags using
git tag <NEW_VERSION>
but signed tags are preferred.
Publish the release with either the GitHub CLI or in a browser. See the GitHub documentation about managing releases.
Check the release workflow runs successfully.
Verify the new version is available from the molecule-plugins page on PyPI.
FAQs
Molecule Plugins
We found that molecule-plugins demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
The Rust Security Response WG is warning of phishing emails from rustfoundation.dev targeting crates.io users.
Product
Socket now lets you customize pull request alert headers, helping security teams share clear guidance right in PRs to speed reviews and reduce back-and-forth.
Product
Socket's Rust support is moving to Beta: all users can scan Cargo projects and generate SBOMs, including Cargo.toml-only crates, with Rust-aware supply chain checks.