
Research
/Security News
Intercomâs npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
@episclera/multipack-core
Advanced tools
đ± A monorepo template repository. Ideal for building shareable JavaScript packages or React modules.
đ± A monorepo template repository. Ideal for building shareable JavaScript packages or React modules.
Site | Getting Started | API | Blog
Lerna structure to build monorepo packagesESLint and Prettier to enforce code style.husky and lint-stagedDocusaurus docs generator preconfigured to work well with Github PagesJest and react-testing-library to test (ts|tsx) files and colect coverage from all packagesGithub workflow actions to run tests after each pushed commitgit clone --depth=1 https://github.com/episclera/multipack.git <YOUR_PROJECT_NAME>npm install and npm run link:packagesRunning npm run link:packages will installing all packages dependencies and linking any cross-dependencies. This command is crucial, as it allows you to use your package names in require() as if the packages were already existing and available in your node_modules folder.
npm run build:packages - build all packages with webpack in production mode
npm run watch:packages - start webpack in watch mode to rebuild packages on each change
npm run watch:packages - start in watch mode (aplications,apis docs) packages
npm run start:packages - build and serve (aplications,apis) packages
npm run version:packages - Bump package versions and Create release tags and Changelogs
npm run publish:packages:npm - publish packages where the latest version is not present in the NPM registry
npm run publish:packages:github - publish packages where the latest version is not present in the GitHub registry
npm run link:packages - will installing all packages dependencies and linking any cross-dependencies in each package
npm run test:packages - run jest tests in each package and colect coverage from all packages
npm run watch:test:packages - run and watch all tests for changes
npm run lint:packages - lint all packages
npm run lint:packages:styles - lint all packages styles
npm run fix:packages - lint and fix all packages
npm run watch:docs - start a Docusaurus server that serve files from /docs folder predestinated for docs.
npm run publish:docs - publish generated docs with Docusaurus to Github Pages
git checkout -b my-new-featuregit commit -am 'Add some feature'git push origin my-new-feature@episclera/multipack © Episclera, Released under the MIT License.
Authored and maintained by Episclera with help from contributors (list).
FAQs
đ± A monorepo template repository. Ideal for building shareable JavaScript packages or React modules.
We found that @episclera/multipack-core demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.