
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
whornbill 环境配置。
npm install -g cage
注意:
npm uninstall -g cage, 再执行上面的命令<>表示参数可以省略
如果一个文件夹下拥有 apps 与 nest 两个文件夹,Cage 就认为它是 whornbill 环境。
cage setup <文件夹名> <svn url>
该操作会更新 rc.json 文件
cage config <文件夹名>
cage c <文件夹名>
Cage 会首先检测当前所处文件夹是否为 whornbill 环境,然后会检测默认的工作空间,如果两者检测皆不通过,会提示警告信息。
cage run
cage r
cage stop
cage s
cage stop all
cage s all
cage sa
cage log
cage l
cage log s
cage l s
cage log js
cage l js
只打开 server 日志所在的文件夹
cage lo
工作空间(workspace): 每一个 whornbill 环境都可以看做一个工作空间,你可以在不同空间中切换。
cage ls
cage update
cage u
cage ip
cage mac
cage hostlist
FAQs
whornbill environment utility.
We found that cage demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.