Research
Security News
Malicious PyPI Package ‘pycord-self’ Targets Discord Developers with Token Theft and Backdoor Exploit
Socket researchers uncover the risks of a malicious Python package targeting Discord developers.
A tool for creating and developing Backbase-Launchpad specific Widgets and Modules.
=========
CLI development tool for widgets / modules
Name | bb-lp-cli |
---|---|
Bundle | tools |
Status | node >=0.12.x < 5.0.x |
Recommended | node 4.6.0 npm 3.x |
General
Dev - Server
npm i bb-lp-cli -g
or
yarn global add bb-lp-cli
Using bblp as binary.
Check all the available commands that you can use.
bblp
or
bblp --help
Check command help
bblp <command> --help
Clone a git repository template. Default is using widget-ng-template
arguments: - template Can be a git repository url or a local folder. options:
bblp generate <template>
Start local development brwserSync server on http://localhost:3000/.
arguments:
options:
./index.dev.html
is the default. You can provide a custom path.bblp start [-a] [-p3030] [-l silent] [--template cxp] [-i] [-e] [-m]
Tests the widget / module using karma test runner and PhantomJS.
arguments:
options:
--browsers Firefox,Chrome,Safari
--config karma.config.js
--moduleDirectories 'target/bower_components'
bblp test
bblp test -c --browsers Firefox,Chrome --moduleDirectories '../../portal/myportal/statics/dist/itemRoot/static/features/[BBHOST]','target/bower_components'
Bundle the widget/module.
arguments:
options:
- f --fulltest with unit tests and linting
- t --withTemplates Bundle HTML templates into build file (for widgets)
- m --withModuleId Build with AMD module ID in definition. Default false
- p --withPerformance Build with performance annotations converted into performance module API calls
--moduleDirectories A comma separated list of the shared components
--moduleDirectories 'target/bower_components'
--webpackconfig Build with custom webpack config
bblp build
with moduleDirectories
bblp build --moduleDirectories '../../portal/myportal/statics/dist/itemRoot/static/features/[BBHOST]','target/bower_components'
Compile & build styles:
Some convention is required to compile styles files (less, scss, css). The name of the main file should be named as:
With custom configuration:
You can specify the autoprefixer query configuration
"autoprefixer": {
"browsers": [
"last 2 versions"
]
}
By default is "last 2 versions".
Bump version in package.json, model.xml, bower.json, README.md and CHANGELOG.md
NOTE if a version property is not found in model.xml file will be created
arguments:
VERSION Semver compliant major [X.x.x], minor [x.X.x] or patch [x.x.X]
[MESSAGE] Optional bump message options:
--suffix - Prerelease suffix name EX. .pre, .beta, .rc, Default .pre
--changelog - CHANGELOG file name Default CHANGELOG.md
--interactive - Confirm next package version Default true
bblp bump minor [increment] "Some relevant message" [--interactive false]
Generating different types of documentation.
arguments:
options:
--api Generate API reference MarkDown in the docs folder. Based on JSDoc annotations. Default
--services Generate reference MarkDown and HTML files in the docs/services folder. based on RAML 0.8 specifications. Optional you can pass the domain name.
Basic Usage:
bblp docs
bblp docs --services https://my.domain.com/services/rest
Use conventional commit messaged. Default will run git commit.
arguments:
options:
bblp commit
How to add your commit convention adapter.
npm i cz-conventional-changelog -D
... configure it after inside the package.json
"config": {
"commitizen": {
"path": "./node_modules/cz-conventional-changelog"
}
}
Register package to launchpad registry endpoints bower - http://launchpad.backbase.com:5678 npm - http://launchpad.backbase.com:8765
arguments:
options:
bblp register [npm]
Unregister package to launchpad registry endpoints
arguments:
options:
bblp unregister [npm] [-f]
Builds a theme. Requires a bower.json file in the directory with a "main" pointing to the base less file
bblp theme build
arguments:
options:
bblp theme build retail [-w --disable-compress -d]
Deploy a package into a running portal.
bblp deploy [--all]
options:
The config for connecting to the portal is obtained by merging multiple configuration files by this order of importance:
Local .bbrc files upwards the directory tree All .bbrc files upwards the directory tree .bbrc file located in user's home folder (~)
The default config is:
{
"scheme": "http",
"host": "localhost",
"port": "7777",
"context": "portalserver",
"username": "admin",
"password": "admin"
}
When used through bblp start -d
it will initially deploy all packages (including bower and
npm dependencies), then watch just the local package and re-deploy on any changes.
This is the default config structure if is not specified otherwise in bower.json file
"config": {
"paths" : {
"scripts": "./scripts",
"docs": "./docs",
"target": "./dist",
"templates": "./templates",
"styles": "./styles",
"test": "./test",
"reports": "./reports",
"index": "./index-dev.html"
},
"data": {
"route": "", // url access to the mock raml api
"files": [
'./**/raml/**/*.raml',
'./**/services/**/*.raml'
]
},
"proxies": {
},
"eslint": "configs/eslint.conf.yaml",
"karma": "configs/karma.conf.yaml"
....
}
By default the cli is looking for an configs folder in the root folder of the app. Possible extensions are on karma options:
Example karma.conf.yaml
# Karma Configuration Options
default:
browsers:
- Chrome
production:
browsers:
- Firefox
- Chrome
Example eslint.conf.yaml
---
rules:
eqeqeq: 0
curly: 2
quotes:
- 2
- "double"
NODE_ENV=production bblp test -c
YAML configuration is preferred format but you can also opt for a .json
format.
The same is possible also for eslint options:
IMPORTANT TO NOTE the file name needs to be karma.conf.yaml
and eslint.conf.yaml
. If you prefer a different name then you can set it up in the bower.json config
...
"karma": "configs/karma.configuration.yaml"
...
@todo
Clone and link the repository
git clone git@github.com:Backbase/bb-lp-cli.git && cd bb-lp-cli && npm link
Use the develop branch
npm install backbase/bb-lp-cli#develop
Publish a beta version
git tag x.x.x-beta.0
git tag push --tags
npm login
npm publish --tags beta
npm info
Q. How can i disable some folders, file, or rules from being linted? A. They are two options: Global and Inline.
1. Global: use a `.eslintignore` file in the root of the project and specify that to ignore, for ex:
```
# Ignore scripts but not the main file
scripts/
!scripts/main.js
```
2. Inline: using a comment inside of your JavaScript file, use the following format
/*eslint-disable */
Install https://chocolatey.org as a good option to use.
choco install git -y
choco install nodist -y
choco install python2 -y
choco install visualstudio2013ultimate -y
...open cmd as "Run as administrator"
npm config set msvs_version 2013 --global
npm config set python /path/to/executable/python2.7
The cli uses node-gyp
You will also need to install:
On Unix:
python
(v2.7
recommended, v3.x.x
is not supported)make
On Mac OS X:
python
(v2.7
recommended, v3.x.x
is not supported) (already installed on Mac OS X)Command Line Tools
via Xcode. You can find this under the menu Xcode -> Preferences -> Downloads
gcc
and the related toolchain containing make
On Windows:
[Python][windows-python] ([v2.7.3
][windows-python-v2.7.3] recommended, v3.x.x
is not supported)
Windows XP/Vista/7:
Windows 7/8:
All Windows Versions
call "C:\Program Files\Microsoft SDKs\Windows\v7.1\bin\Setenv.cmd" /Release /x86
call "C:\Program Files\Microsoft SDKs\Windows\v7.1\bin\Setenv.cmd" /Release /x64
If you have multiple Python versions installed, you can identify which Python
version node-gyp
uses by setting the '--python' variable:
$ node-gyp --python /path/to/python2.7
If node-gyp
is called by way of npm
and you have multiple versions of
Python installed, then you can set npm
's 'python' config key to the appropriate
value:
FAQs
A tool for creating and developing Backbase-Launchpad specific Widgets and Modules.
The npm package bb-lp-cli receives a total of 10 weekly downloads. As such, bb-lp-cli popularity was classified as not popular.
We found that bb-lp-cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover the risks of a malicious Python package targeting Discord developers.
Security News
The UK is proposing a bold ban on ransomware payments by public entities to disrupt cybercrime, protect critical services, and lead global cybersecurity efforts.
Security News
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.