
Research
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
A simple CLI for scaffolding eeui projects, we provide eeui-template to quickly build small and medium sized app.
eeui-cli 是 配合 eeui 框架使用的命令行工具
npm i eeui-cli -g
如果出现permission denied等相关权限的错误提示,请使用管理员身份或root身份运行,如 mac:sudo npm i eeui-cli -g。
npm update eeui-cli -g
eeui create [projectName]
eeui-demo)eeui update
eeui dev
eeui build
eeui vue [pageName]
eeui plugin [command] [pluginName]
install,卸载:uninstall,修复:repair,创建:create,发布:publish)repair时pluginName可留空。//安装插件示例:
eeui plugin install pay
//卸载插件示例:
eeui plugin uninstall pay
//修复插件示例:
eeui plugin repair
//创建插件示例:
eeui plugin create pluginDemo
//发布插件示例:
eeui plugin publish pluginDemo
eeui setting
eeui setdemo
eeui repair
eeui icons [id]
eeui launchimage [id]
eeui login
eeui logout
eeui backup
eeui recovery
eeui -v // 查看当前cli版本
eeui -h // 命令帮助信息
FAQs
A simple CLI for scaffolding eeui projects, we provide eeui-template to quickly build small and medium sized app.
We found that eper-cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.

Security News
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.