Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
expo-cli
Advanced tools
If you have problems with the code in this repository, please file issues & bug reports at https://github.com/expo/expo-cli. Thanks!
Installation instructions and documentation here.
To make a new project use expo init [path]
. The path is optional and it will use the current directory if not specified (all commands that need a path behave similarly).
To view a project you must have an Expo CLI server running for that project. Run expo start [path]
to start running the server. Once it is ready it'll output a URL for your project.
The server will continue running until you close it.
To view this on your phone, do the following:
Go get the Expo app on your Android or iOS device. It's available on the Google Play Store and on the iOS App Store.
Run expo send
to send a link via email. You can also use the --send-to
option when running expo start
.
Check your e-mail and tap the link. The Expo app should open and you should be able to view your experience there!
To publish something you've made, just follow these steps:
expo login
.expo start
.expo publish
. A few seconds later, you should get a clean URL sent to you that points to the exp.host server where your package was published to.You can publish as many times as you want and it will replace your old version, so don't worry about making a mistake!
FAQs
The command-line tool for creating and publishing Expo apps
The npm package expo-cli receives a total of 34,080 weekly downloads. As such, expo-cli popularity was classified as popular.
We found that expo-cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 33 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.