
Security News
Crates.io Users Targeted by Phishing Emails
The Rust Security Response WG is warning of phishing emails from rustfoundation.dev targeting crates.io users.
@omcfe/ufe-dev-dependencies
Advanced tools
This project is used for pulling UFE dev dependencies.
Clone the project from git, then run npm i
, then npm run update
. It will try to get the latest dependencies and modify package.json accordingly. If there are changes, you should add and comit the package.json
file.
A new release can be done by running npm version patch|minor|major
. It will try and isntall the dependencies, and, if everything is good, it will create a new git tag and push everything to the git remote.
A special reelase pipeline will then be triggered for the newly created tag, and it will
Ex:
npm i
npm run update
npm commit -am 'Updated dependencies'
npm version patch
FAQs
UFE Dev Dependencies
We found that @omcfe/ufe-dev-dependencies demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
The Rust Security Response WG is warning of phishing emails from rustfoundation.dev targeting crates.io users.
Product
Socket now lets you customize pull request alert headers, helping security teams share clear guidance right in PRs to speed reviews and reduce back-and-forth.
Product
Socket's Rust support is moving to Beta: all users can scan Cargo projects and generate SBOMs, including Cargo.toml-only crates, with Rust-aware supply chain checks.