Security News
The Risks of Misguided Research in Supply Chain Security
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.
@kids-reporter/draft-editor
Advanced tools
yarn install
@mirrormedia/lilith-draft-editor
export @mirrormedia/lilith-core
所需要的 RichTextEditor
,而 @mirrormedia/lilith-core
則是被 @mirrormedia/lilith-(mirrormedia|readr|mesh|editools)
所使用,因此在開發上會以各網站的角度去切入,在本套件中修改 editor 相關的程式碼,並在 lilith-(mirrormedia|readr|mesh|editools) 中測試開發狀況。
舉 lilith-mirrormedia 為例,要修改 mirrormedia 相關的 RichTextEditor 需要在 packages/lilith-draft-editor
中進行改動,改動完之後跑 yarn build
產生 transpiled 後的程式碼,若 packages/lilith-draft-editor
有修改 package.json 中的套件版本時,則需要同時修改 packages/core
中 import @mirrormedia/lilith-draft-editor
的版本; 同理,若是因此 packages/core
有修改版本號的話也需要跑 yarn build
, packages/mirrormedia
也同樣需要修改 import @mirrormedia/lilith-core
的版本。
因為 lilith-mirrormedia, lilith-core, lilith-draft-editor 都在 monorepo 中,yarn workspaces 會為 lilith-core, lilith-draft-editor pkg 建立 soft link,將 node_modules/@mirrormedia/lilith-core
指到 packages/core
而 node_modules/@mirrormedia/lilith-draft-editor
指到 packages/draft-editor
,所以 yarn build
產生的新的程式碼,可以不需要透過 npm publish 和 yarn install 的方式,立即讓 lilith-mirrormedia, lilith-core 使用。
等到確定程式碼修改完畢後,我們再將最新的程式碼上傳(npm publish
)到 npm registry 去,讓 lilith-editools 的 CI/CD 可以下載到最新的版本。
在 src
資料夾下有兩大類的檔案
依照各網站需求修改src/website/${website}/
中的檔案
*注 1: lilith-draft-editor 各個 buttons 對應的 block-renderers, entity-decorators 會 maintain 在 lilith-draft-renderer,由各網站 Next.js 專案開發人員實作,在本專案中會直接將 lilith-draft-renderer 中定義好的 block-renderers, entity-decorators 直接使用(除了少數需要再編輯的 block-renderer,參考 src/website/${website}/block-renderer
中的 editor wrapper component)。
*注 2: 雖然各個網站都 maintain 了一個 draft-editor,可以自行決定 import 進來的 buttons,不過因為 lilith-core 中實作 disalbedButtons 的功能,所以目前一率將所有的 buttons 加入 RichTextEditor 中,由 lilith-(mirrormedia|readr|mesh|editools) 來控制所使用的 buttons。
yarn build
npm run publish
在 publish 前,請根據 conventional commits 的規範,將 package.json#version 升版。
views/
folder, we transpile them specifically.For those files under views/
folder, we transpile them by babel according to different configuation.
The specific babel configuration is .views.babelrc.js
.
In .views.babelrc.js
, we tell babel not to transpile import
and export
es6 codes into commonJS codes.
The Keystone server won't start server well if those files under views/
are transpiled into commonJS codes.
FAQs
Unknown package
The npm package @kids-reporter/draft-editor receives a total of 20 weekly downloads. As such, @kids-reporter/draft-editor popularity was classified as not popular.
We found that @kids-reporter/draft-editor demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.