Security News
Research
Supply Chain Attack on Rspack npm Packages Injects Cryptojacking Malware
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
@easyv/react-component-builder
Advanced tools
src 开发界面源码 dev 开发界面构建工具 lib 开发界面打包文件 launcher react开发环境构建 launcher/generate.js easyv-cli的generate命令会调它 demos 本地开发环境调试 scripts
src 开发界面源码 dev 开发界面构建工具 lib 开发界面打包文件 launcher react开发环境构建 launcher/generate.js easyv-cli的generate命令会调它 demos 本地开发环境调试 scripts 本地开发环境测试用脚本 templates 组件模版目录 用于easyv-cli快速创建组件模版
往npmjs上推包注意事项
FAQs
Unknown package
The npm package @easyv/react-component-builder receives a total of 2 weekly downloads. As such, @easyv/react-component-builder popularity was classified as not popular.
We found that @easyv/react-component-builder demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.
Security News
Sonar’s acquisition of Tidelift highlights a growing industry shift toward sustainable open source funding, addressing maintainer burnout and critical software dependencies.