
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@megalo/cli-plugin-eslint
Advanced tools
eslint plugin for megalo-cli
megalo-cli-service lint
Usage: megalo-cli-service lint [options] [...files]
Options:
--format [formatter] specify formatter (default: codeframe)
--no-fix do not fix errors
--max-errors specify number of errors to make build failed (default: 0)
--max-warnings specify number of warnings to make build failed (default: Infinity)
检查提示以及修复文件格式。 如果没有特别指定文件或目录,默认情况下它会检查 src
和 test
目录下的所有文件
另外 ESLint CLI options 这里的选项也是支持的.
ESLint可以通过 .eslintrc
或 package.json
中的 eslintConfig
字段进行配置。
默认情况下启用 eslint-loader
进行开发时的保存。 可以使用 megalo.config.js
中的 lintOnSave
选项禁用它:
module.exports = {
lintOnSave: false
}
设置为 true
时,eslint-loader
会将 lint 错误输出为编译警告。默认情况下,警告仅仅会被输出到命令行,且不会使得编译失败。
如果你希望让 lint
错误在开发时直接显示在浏览器中,你可以使用 lintOnSave: 'error'
。这会强制 eslint-loader
将 lint
错误输出为编译错误,同时也意味着 lint
错误将会导致编译失败。
或者,你也可以通过设置让浏览器 overlay
同时显示警告和错误:
// megalo.config.js
module.exports = {
// 编译小程序不支持该选项
devServer: {
overlay: {
warnings: true,
errors: true
}
}
}
当 lintOnSave
是一个 truthy 的值时,eslint-loader
在开发和生产构建下都会被启用。如果你想要在生产构建时禁用 eslint-loader
,你可以用如下配置:
// megalo.config.js
module.exports = {
lintOnSave: process.env.NODE_ENV !== 'production'
}
config.module.rule('eslint')
config.module.rule('eslint').use('eslint-loader')
FAQs
eslint plugin for megalo-cli
We found that @megalo/cli-plugin-eslint demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.