
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
cnchar-data
Advanced tools
该库为cnchar的资源cdn库
也可以用于支持离线化使用cnchar部分在线资源,及生产环境部署到自己的服务器中
npm i cnchar-data -D
首先配置 package.json scripts
{
...,
"scripts": {
"cnchar-serve": "cnchar-serve 3002",
"cnchar-prod": "cnchar-serve-prod"
},
}
运行一个本地的服务,端口可以自定义
npm run cnchar-serve
运行成功之后可以访问一下链接查看是否正确运行
http://localhost:3002/draw/一.json
import cnchar from 'cnchar';
cnchar.setResourceBase('http://localhost:{port}/')
如需将资源部署到您的生产环境服务器
请执行
npm run cnchar-prod
会在项目根目录生成cnchar-data目录, 将改文件夹放置在您的http服务器中
假设可访问路径为 https://www.xxx.com/cnchar-data/
则对cnchar设置如下
import cnchar from 'cnchar';
cnchar.setResourceBase('https://www.xxx.com/cnchar-data/')
export const name: 'cnchar-data';
export const words: {
dict: string;
}
export function serve(port?: number): void;
export function build(): void;
export default {
name,
words,
serve,
build,
}
import {serve} from 'cnchar-data';
serve(port);
import {build} from 'cnchar-data';
build();
npm i cnchar-data -g
cnchar-serve [port]
cnchar-serve-prod
FAQs
cnchar的资源库
The npm package cnchar-data receives a total of 2,031 weekly downloads. As such, cnchar-data popularity was classified as popular.
We found that cnchar-data demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.