Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
The command line tool to build, deploy and manage Cordova-based applications.
Apache Cordova allows for building native mobile applications using HTML, CSS and JavaScript. This tool helps with management of multi-platform Cordova applications as well as Cordova plugin integration.
In your command-line on Windows:
c:\> npm install -g cordova
In your terminal on Mac OS X/Linux:
$sudo npm install -g cordova
This simple example demonstrates how Cordova CLI can be used to create a myApp
project with the camera
plugin and run it for android
platform:
cordova create myApp com.myCompany.myApp myApp
cd myApp
cordova plugin add cordova-plugin-camera --save
cordova platform add android --save
cordova requirements android
cordova build android --verbose
cordova run android
Cordova is an open source Apache project and contributors are needed to keep this project moving forward. Learn more on how to contribute on our website.
If you find issues with the Cordova CLI, please follow our guidelines for reporting issues. Please bear in mind that most of cordova-cli
's functionality is implemented in cordova-lib, so that could be the place to report your issue.
Platform-specific issues should be reported in the relevant repositories, such as cordova-android and cordova-ios.
FAQs
Cordova command line interface tool
The npm package cordova receives a total of 40,065 weekly downloads. As such, cordova popularity was classified as popular.
We found that cordova demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 28 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.