
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
brain-vue-cli
Advanced tools
基于vue by webpack 再次封装,提取少量配置,用来灵活处理打包问题,支持多入口,及多套环境配置指令方式切换以及按需构建入口文件。
npm i brain-vue-cli -g 或者npm i brain-vue-cli --D
package.json{
"scripts":{
"dev": "brain-vue-cli dev", //开发环境
"dev1": "brain-vue-cli dev app1", //开发环境 按需构建入口文件
"build": "brain-vue-cli prod",//生产环境
"build:dist": "brain-vue-cli dist",//预发布环境
"build:test": "brain-vue-cli test",//测试环境
"build:report": "brain-vue-cli report" // 生成包大小分析服务
}
}
在以前我们切换环境一般都是通过process.env.NODE_ENV值来判定,但这样子有一定的局限性,我们无法区分测试环境和线上环境,这时我们将无法快捷切换测试环境配置和线上环境配置,或许我们还能通过分支来区分,但这样一来将需要建立多个环境分支,有一定的分支管理成本,而且也不是非常好的办法。现在我们可以通过process.env.environment来区分不同环境的构建。
MIT license
FAQs
A command line tool used to run projects
We found that brain-vue-cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.