
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@quick-game/cli
Advanced tools
@quick-game/cli为开发者提供的联盟快游戏命令行工具
安装 @quick-game/cli 后,便可使用 qg 命令。安装方法如下:
npm install -g @quick-game/cli
qg init <project-name> [-t <template>] [-c <cwd dir>] [-f]
project-name要创建的联盟快游戏工程的名称。可以为 . ,当 project-name 为.时表示在当前目录创建联盟快游戏工程。
-t指定创建联盟快游戏工程使用的模板,默认为default,表示使用默认的模板。不指定该参数时就使用默认的模板。
目前只有
default模板,所以该参数可以不指定,使用默认值即可
-c指定创建联盟快游戏工程的目录,不指定该参数时,使用process.cwd()也就是当前执行目录来创建,如果指定 了路径,就在指定路径创建。
-f如果指定的 project-name 目录已经存在,会提示用户是 '覆盖' 还是 '合并',指定 -f 或者 --force 可以忽略提示,直接强制覆盖
//在当前路径创建名为abc的联盟快游戏工程
qg init abc
//在当前路径创建名为abc的联盟快游戏工程,如果已经存在 abc 则强制覆盖
qg init abc -f
//在当前路径直接创建联盟快游戏工程,假设当前路径为`/usr/name/demoGame/`,联盟快游戏工程名为demoGame
qg init .
// 在 `/usr/name/documents/`路径创建名为abc的联盟快游戏工程
qg init abc -c /usr/name/documents/
// 在 `/usr/name/demoGame/`路径直接创建联盟快游戏工程,即联盟快游戏工程名为 demoGame
qg init . -c /usr/name/demoGame/
命令执行后,会在当前目录下创建文件夹,作为项目根目录,这个项目已经包含了项目配置与游戏入口的初始代码,项目根目录主要结构如下:
├── sign rpk包签名模块
│ └── debug 调试环境
│ ├── certificate.pem 证书文件
│ └── private.pem 私钥文件
├── src
│ ├── image 图片资源目录
│ │ └── logo.png 游戏图标
│ ├── js 游戏业务逻辑目录
│ | └── main.js 游戏业务逻辑代码
│ ├── game.js 游戏入口js
│ └── manifest.json 项目配置文件,配置游戏图标、包名等
└── package.json 定义项目需要的各种模块及配置信息Copy to clipboardErrorCopied
目录的简要说明如下:
src:项目源文件夹
sign:签名模块,当前仅有debug签名,如果内测上线,请添加release文件夹,增加release签名;签名生成:
openssl req -newkey rsa:2048 -nodes -keyout private.pem -x509 -days 3650 -out certificate.pem
qg build
qg release
编译打包成功后,项目根目录下会生成文件夹:build、dist:
release签名,建议cp提前生成好。签名需要保存的其他地方,用于后续更新打包。qg server
FAQs
Command line interface for rapid qg development
We found that @quick-game/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.