
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@ldesign/common
Advanced tools
公共库包含公共样式与工具函数,各框架以子仓库的形式引入此仓库。
|-- style // 组件库 UI 开发
|-- web // web UI 开发
|-- mobile // mobile UI 开发
|-- js // 组件库公用函数
分支拉取规则:网页组件使用 feature/web/_ ;移动端组件使用 feature/mobile/_ ;小程序使用 feature/mp/* 。
具体示例如下,
feature/web/button
feature/mobile/button
feature/mp/button
FAQs
LDesign UI 样式库以及组件库公共函数(js)
The npm package @ldesign/common receives a total of 1 weekly downloads. As such, @ldesign/common popularity was classified as not popular.
We found that @ldesign/common demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.