
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
ehdev-configer-spa
Advanced tools
配置项 | 默认值 | 说明 |
---|---|---|
buildPath | dist | 输出目录 |
enableHotModuleReplacement | true | 启用热更新 |
framework | raect | 依赖框架,目前只对 react 有做优化,包括引入 react-hot-loader |
htmlWebpackPlugin | {inject: true, chunksSortMode: 'auto', cache: true, showErrors: true} | htmlWebpackPlugin 插件配置, 参考 https://github.com/jantimon/html-webpack-plugin#configuration |
browserSupports | last 2 version | 浏览器支持配置,影响 babel 和 autoprefixer , 配置参考:https://github.com/ai/browserslist |
dll | { enable: false, enclude: [] } | 是否启用 dll,enclude 提供打入 dll 包的模块 |
providePluginConfig | {} | 主要用来支持 jQuery 依赖全局挂载的老模块, 参考 [https://webpack.js.org/plugins/provide-plugin/] |
(https://webpack.js.org/plugins/provide-plugin/) | ||
babelUseBuiltIns | true | babel-preset-env#usebuiltins 配置 |
https | false | 开发环境的 https 支持 |
publicPath | ../ | webpackConfig.output.publicPath , 只在构建时生效 |
contentBase | undefined | 配置 devServer 的 contentBase,默认包含当前项目的输出目录,不需要配置 |
引用 svg 路径后加上 ?reactComponnet
,svg 会被转换成 react component
否则 svg 会被当成普通的资源文件,使用 file-loader 加载
import Foo from './foo.svg?reactComponnet';
<Foo />
v0.1.4
FEATURE:
FAQs
ehdev-shell's config for spa project
We found that ehdev-configer-spa demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.