
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
esbuild-plugin-remove-import-type
Advanced tools
按开发环境的要求,运行和调试项目
运行和调试组件
pnpm run dev
运行测试用例
pnpm run test
按照社区规范和最佳实践,生成构建产物
pnpm run build
继续创建更多项目要素
pnpm run new
其他
pnpm run lint # 检查和修复所有代码
pnpm run change # 添加 changeset,用于发版时生成 changelog
pnpm run bump # 生成发版相关的修改,比如更新版本号、生成 changelog
pnpm run release # 根据 bump 自动修改和人工修改的发版要求,发布项目
FAQs
remove import-type in third party dependencies
We found that esbuild-plugin-remove-import-type demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.