
Research
Malicious Go “crypto” Module Steals Passwords and Deploys Rekoobe Backdoor
An impersonated golang.org/x/crypto clone exfiltrates passwords, executes a remote shell stager, and delivers a Rekoobe backdoor on Linux.
@ui5/create-webcomponents-package
Advanced tools
UI5 Web Components - Create PackageProvides an npm init script for creating new "UI5 Web Components" packages.
Usage:
# npm 6.x
npm init @ui5/webcomponents-package [OPTIONS]
# npm 7+, an extra double-dash is needed:
npm init @ui5/webcomponents-package -- [OPTIONS]
Options:
--name <string> - defines the package name
--test-setup <"cypress" | "manual"> - defines whether the predefined test setup should be added or it will be configured manually.
--skip - skips configuration and generates package with a default value for each parameter that wasn't passed
The script creates a new directory, and fills it with a package.json file and all necessary source files, and resources for a new
components package.
Usage:
yarn create @ui5/webcomponents-package [OPTIONS]
Options:
--name <string> - defines the package name
--test-setup <"cypress" | "manual"> - defines whether the predefined test setup should be added or it will be configured manually.
--skip - skips configuration and generates package with a default value for each parameter that wasn't passed
The script creates a new directory, and fills it with a package.json file and all necessary source files, and resources for a new
components package.
We welcome all comments, suggestions, questions, and bug reports. Please follow our Support Guidelines on how to report an issue, or chat with us in the #webcomponents channel of the OpenUI5 Community Slack.
Please check our Contribution Guidelines.
Copyright (c) 2019 SAP SE or an SAP affiliate company. All rights reserved. This file is licensed under the Apache Software License, Version 2.0 except as noted otherwise in the LICENSE file.
FAQs
UI5 Web Components: create package
The npm package @ui5/create-webcomponents-package receives a total of 24 weekly downloads. As such, @ui5/create-webcomponents-package popularity was classified as not popular.
We found that @ui5/create-webcomponents-package demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
An impersonated golang.org/x/crypto clone exfiltrates passwords, executes a remote shell stager, and delivers a Rekoobe backdoor on Linux.

Security News
npm rolls out a package release cooldown and scalable trusted publishing updates as ecosystem adoption of install safeguards grows.

Security News
AI agents are writing more code than ever, and that's creating new supply chain risks. Feross joins the Risky Business Podcast to break down what that means for open source security.