
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
@eggjs/development
Advanced tools
This is an egg plugin for local development, under development environment enabled by default, and closed under other environment.
@eggjs/development
has been built-in for egg. It is enabled by default.
see config/config.default.ts for more detail.
Under the following directory (including subdirectories) will watch file changes under development environment by default, trigger an Egg development environment server reload:
set
config.development.overrideDefault
totrue
to skip defaults merge.
Under the following directory (including subdirectories) will ignore file changes under development environment by default:
set
config.development.overrideIgnore
totrue
to skip defaults merge.
Developer can use config.reloadPattern
(multimatch) to control whether to reload.
// config/config.default.ts
export default = {
development: {
// don't reload when css fileChanged
// https://github.com/sindresorhus/multimatch
reloadPattern: ['**', '!**/*.css'],
},
};
You can view loader trace for performance issue from http://127.0.0.1:7001/__loader_trace__
Please open an issue here.
Made with contributors-img.
4.0.0 (2025-01-11)
part of https://github.com/eggjs/egg/issues/3644
https://github.com/eggjs/egg/issues/5257
<!-- This is an auto-generated comment: release notes by coderabbit.ai -->Based on the comprehensive changes, here are the release notes:
New Features
Breaking Changes
egg-development
to @eggjs/development
Improvements
Bug Fixes
Chores
FAQs
development tool for egg
The npm package @eggjs/development receives a total of 59 weekly downloads. As such, @eggjs/development popularity was classified as not popular.
We found that @eggjs/development demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 13 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.