
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@we-weaver/core
Advanced tools
本文旨在让用户在5分钟左右的时间对 weaver 有个快速的了解,更详细的解读与梳理敬请关注我们后续的系列文章。
weaver是一套面向通用场景,高效、高扩展性、低学习成本、渐进式接入的系统搭建方案。
随着业务的发展,我们发现中后台系统,甚至是相当部分的前台系统,期望能够 多快好省 搭建应用的述求越来越多。
经过梳理我们不难发现:在产品 - UI - 前端- 后端 - 测试,这一完整的研发流程中,大部分系统可以极大的复用之前已有的生产资料,包括不限于:标准化的产品输出、标准化的 UI 视觉稿、标准化的前端(交互、逻辑)组件、模式化的业务接口。
基于这一现状,从前端出发而有不止于前端,我们针对上下游配合方设计了一套可落地,易协作的研发解决方案 Weaver,这也决定了我们的设计初衷:
易用性
我们追求低上手成本,期望能给研发链路上的所有人带来便捷:
平台化
我们期望提供平台级的研发入口中枢,他拥有以下特性:
FAQs
> 本文旨在让用户在5分钟左右的时间对 weaver 有个快速的了解,更详细的解读与梳理敬请关注我们后续的系列文章。
We found that @we-weaver/core demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.