
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@vnmfjs/vnmf-loader
Advanced tools
@vnmfjs/vnmf-loader
暴露给 @vnmfjs/mini-runner
和 @vnmfjs/webpack-runner
使用的 Webpack loader,包含以下 loader
:
小程序专用。在小程序入口文件调用 @vnmfjs/runtime
的 createReactApp
/createVueApp
方法创建一个小程序 App
构造函数接受的对象。
framework
: 框架类型,'react' | 'nerv' | 'vue' | 'vue3'
prerender
: 预渲染配置小程序专用。在小程序页面文件调用 @vnmfjs/runtime
的 createPageConfig
方法创建一个小程序 Page
构造函数接受的对象。
framework
: 框架类型,'react' | 'nerv' | 'vue' | 'vue3'
name
: 页面路径小程序专用。在小程序页面文件调用 @vnmfjs/runtime
的 createComponentConfig
方法创建一个小程序 Component
构造函数接受的对象。
framework
: 框架类型,'react' | 'nerv' | 'vue' | 'vue3'
name
: 页面路径H5 专用。在小程序入口文件调用 @vnmfjs/router
的 createRouter
方法创建兼容小程序生命周期和路由系统的应用。
framework
: 框架类型,'react' | 'nerv' | 'vue' | 'vue3'
config
: 应用配置,对应 app.config.jspages:页面配置,对应
page.config.jsfilename
: 文件名FAQs
Vnmf runner use webpack loader
We found that @vnmfjs/vnmf-loader demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.