Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
edp-provider-rider
Advanced tools
edp
的 rider
支持模块。
为 edp-webserver
和 edp-build
提供了预定配置。
集成了 stylus
, rider
, autoprefixer-core
, css-mqpacker
, husl
等依赖。
npm install edp-provider-rider --save-dev
注:使用 edpx-mobile
生成的项目已经内置了 edp-provider-rider
。
在 edp-webserver-config.js
与 edp-build-config.js
顶部引入:
var epr = require('edp-provider-rider');
exports.stylus = epr.stylus;
// 默认配置
var stylusPlugin = epr.plugin();
在 edp-webserver-config.js
对应部分添加:
autostylus({
stylus: epr.stylus,
use: stylusPlugin
})
在 edp-build-config.js
对应部分添加:
new StylusCompiler({
stylus: epr.stylus,
compileOptions: {
use: stylusPlugin
}
})
搞定!
在定义 stylusPlugin
时,可以向 .plugin()
传入定制参数:
// 扩展配置,参数都是可选的
var stylusPlugin = epr.plugin({
// 隐式引入 rider,默认为 true
implicit: true,
// 是否解析 url 中的路径,默认为 true
resolveUrl: true,
// autoprefixer 配置,以下为默认值,可设置 false 禁用
// 参考:https://github.com/postcss/autoprefixer-core
autoprefixer: ['Android >= 2.3', 'iOS >= 6', 'ExplorerMobile >= 10'],
// husl 配置,默认为 false
// 参考:http://www.boronine.com/husl/
husl: true,
// mqpacker 启用状态,默认为 true
// 参考:https://github.com/hail2u/node-css-mqpacker
mqpacker: true,
// 手动追加 stylus 配置,可在此处引入其它 stylus 插件
// 参考:http://stylus-lang.com/docs/js.html#usefn
use: function(style) {}
});
MIT © Baidu Inc.
FAQs
edp 的 rider 支持模块,为 webserver 和 build 命令提供了预定配置
We found that edp-provider-rider demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.