
Research
/Security News
Popular Go Decimal Library Targeted by Long-Running Typosquat with DNS Backdoor
A long-running Go typosquat impersonated the popular shopspring/decimal library and used DNS TXT records to execute commands.
@bbfe/components-assembly
Advanced tools
组件合集,代理不同 UI 组件库
目前支持 ElementUI,目的是扩展组件功能,修改组件样式
采用 ant.design 设计思想
{
"vue": "2.5.13",
"element-ui": "^2.0.10"
}
注意,vue 2.4 和 2.5 在 scopedSlots 语法的属性名上有修改,本库使用的 vue 2.5.13,如有使用 scopedSlot 请使用 template scope 写法
** components-assembly 1.x.x 版本,需要升级vue,vue-template-compiler 和 element-ui **
通过 mixins 混入组件,扩展组件方法和属性
完全编译 css 替代原组件库样式
FAQs
UI components assembly for Vue.js, proxy UI library
We found that @bbfe/components-assembly demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
A long-running Go typosquat impersonated the popular shopspring/decimal library and used DNS TXT records to execute commands.

Research
Active npm supply chain attack compromises @antv packages in a fast-moving malicious publish wave tied to Mini Shai-Hulud.

Security News
/Research
Socket detected malicious node-ipc versions with obfuscated stealer/backdoor behavior in a developing npm supply chain attack.