
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
@tolgee/cli
Advanced tools
A CLI tool to interact with Tolgee directly from your terminal.
The Tolgee CLI lets you pull strings from the Tolgee platform into your projects, push local strings to the Tolgee platform, extract strings from your code, and much more!

The Tolgee CLI is published as a NPM package. You simply need to install it, and you're good to go!
# npm
npm i --global @tolgee/cli
# Yarn
yarn global add @tolgee/cli
# pnpm
pnpm add --global @tolgee/cli
See our documentation for more information.
Alternatively, you can use the Docker image:
# Pull the latest image
docker pull tolgee/cli:latest
# Run directly
docker run --rm tolgee/cli:latest --help
# Create an alias for easier usage
alias tolgee="docker run --rm -v \$(pwd):/workspace -w /workspace tolgee/cli:latest"
The Docker images are available on Docker Hub and support multiple platforms (linux/amd64, linux/arm64).
Once installed, you'll have access to the tolgee command. Run tolgee help to see all the supported commands, their
options and arguments.
Make sure to give the docs a look!
Contributions are welcome! Check out HACKING.md for some information about the project internals and information about the workflow.
🧀
FAQs
A tool to interact with the Tolgee Platform through CLI
The npm package @tolgee/cli receives a total of 43,872 weekly downloads. As such, @tolgee/cli popularity was classified as popular.
We found that @tolgee/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.