
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
The Expo Development CLI
If you have problems with the code in this repository, please file issues & bug reports at https://github.com/expo/expo. Thanks!
Installation instructions and documentation here.
To make a new project use exp init [path]
. The path is optional and it will use the current directory if not specified (all commands that need a path behave similarly).
To view a project you must have an exp
server running for that project. Run exp start [path]
to start running the server. Once it is ready it'll output a url for your project.
$ exp start
...
[exp] Your URL is
exp://3h-xu5.jesse.expo-example.exp.direct
The server will continue running until you close it.
To view this on your phone, do the following:
Go get the Expo app on your Android or iOS device. It's available on the Google Play Store and on the iOS App Store.
Run exp send
to send a link via email or text. You can also use the --send-to
option when running exp start
.
Check your e-mail or texts and tap the link. The Expo app should open and you should be able to view your experience there!
To publish something you've made, just follow these steps:
Create an Expo account or login to an existing one by running exp login
.
Run an exp
server using exp start
.
Check to make sure you can load your app by sending the link to yourself with exp send
and opening it in the Expo app.
Once everything looks good, run exp publish
. A few seconds later, you should get a clean URL sent to you that points to the exp.host server where your package was published to.
You can publish as many times as you want and it will replace your old version, so don't worry about making a mistake!
FAQs
The command-line tool for creating and publishing Expo apps
The npm package exp receives a total of 372 weekly downloads. As such, exp popularity was classified as not popular.
We found that exp demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 9 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.