
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
@deepjs/cli
Advanced tools
小工具,将重复简单的工作,使用工具来处理
为什么需要需要脚手架?
减少重复性的工作,不再需要复制其他项目再删除无关代码,或者从零创建一个项目和文件。
根据交互动态生成项目结构和配置文件等。
多人协作更为方便,不需要把文件传来传去。
使用(参考 @vue/cli)
jscli create <template> <name>jscli add <template> <name>
模板管理(参考 npm config & nrm 的形式)
~/.jsclircjscli tpls ls [--json]jscli tpls add <key> <value>jscli tpls del <key>jscli tpls edit,调用默认编辑器编辑(也可以考虑使用 VIM)jscli tpls check参考:
FAQs
Command line interface for rapid js development
We found that @deepjs/cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.