New Research: Supply Chain Attack on Axios Pulls Malicious Dependency from npm.Details
Socket
Book a DemoSign in
Socket

bri-components

Package Overview
Dependencies
Maintainers
3
Versions
348
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

bri-components

a component lib for vue project

latest
npmnpm
Version
1.6.13
Version published
Weekly downloads
917
3062.07%
Maintainers
3
Weekly downloads
 
Created
Source

bri-components

A Vue.js project

Build Setup

# install dependencies
npm install

# serve with hot reload at localhost:8080
npm run dev

# build for production with minification
npm run build

# build for production and view the bundle analyzer report
npm run build --report

# run unit tests
npm run unit

# run e2e tests
npm run e2e

# run all tests
npm test

For a detailed explanation on how things work, check out the guide and docs for vue-loader.

保证npm登录状态 npm login

前端正常npm包发布流程 bri-components:(此包简单,不用压缩) npm version patch npm publish

bri-datas和bri-utils: 第一次操作的,先准备以下(之后发包不用重复操作) -package.json里改成"main": "lib/bri-datas.min.js"(指向压缩文件) -git stash save 发包步骤 npm version patch git stash apply npm run lib:prod npm publish git push git reset origin/dev --hard

前端项目应急npm包发布流程(尽量避免发应急包) 需发布npm预发布号的包: 找到项目包使用包的version git checkout -b (eg: git checkout -b dsh v1.4.7) git push --set-upstream origin 修改 => commit 发包(此时用npm version release) git checkout dev git merge git branch -d git push origin -d git checkout dev

除外需将所有tag推向remote(偶尔操作一下即可) git push --tags

另:修改npm包前最好先git pull(频繁发包,这种习惯log记录清晰)

Keywords

editor

FAQs

Package last updated on 10 Dec 2025

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts