
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
Documentation Generation for BuckleScript projects
Read more in the docs: BsDoc
Install in your project using npm or yarn:
$ yarn add bsdoc
And whenever you want to generate your docs you can run:
# Build your docs!
MyProject $ yarn run bsdoc build MyProject
yarn run v1.12.3
$ ./node_modules/.bin/bsdoc build MyProject
info: Compiling documentation for package "MyProject"...
info: Generating .html files...
info: Done ✅
✨ Done in 0.58s.
Additionally, to install the support files (default CSS and Javascript), you can run:
# Create the support files
MyProject $ yarn run bsdoc support-files
yarn run v1.12.3
$ ./node_modules/.bin/bsdoc support-files
info: Copying support files (CSS, JS) into ./docs
info: Done ✅
✨ Done in 0.53s.
bsdoc is developed as a Native Reason project, and is only possible thanks to
esy, dune, and, naturally, odoc.
If you haven't installed Esy yet, follow the instructions in their web site: https://esy.sh
After you have done that, you need only run esy build to get the project
bootstrapped.
Unfortunately I haven't gotten around publishing bsdoc for Linux/Windows, but if you have npm installed you can run:
$ esy build
$ esy npm-release
And that'll get you an npm package that you can then install locally (or globally) in any of your projects. Be mindful that it'll only work for bs-platform@6+ projects!
FAQs
> Documentation Generation for BuckleScript projects
We found that bsdoc demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.