Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
expo-library
Advanced tools
> CLI for creating reusable, modern Expo libraries using [watchwoman](http://npmjs.com/package/watchwoman) and expo init.
CLI for creating reusable, modern Expo libraries using watchwoman and expo init.
This package requires node >= 10
.
before install expo-library
install watchwoman
like this
npm i -g watchwoman
then install expo-library
npm install -g expo-library
expo-library
Answer some basic prompts about your module, and then the CLI will perform the following steps:
Local development is broken into two parts (ideally using two tabs).
First, run yarn start
to watch your yourpackage
module and automatically add into exmaple/node_modules/yourpackage
whenever you make changes.
npm start # runs watcher of watchwoman
The second part will be running the example/
create-expo-app that's linked to the local version of your module.
# (in another tab)
cd example
npm start # runs your expo app bundler
Now, anytime you make a change to your library in src/
or to the example app's example/src
, create-expo-app
will live-reload your local dev server so you can iterate on your component in real-time.
npm publish
This builds commonjs
and es
versions of your module to dist/
and then publishes your module to npm
.
Make sure that any npm modules you want as peer dependencies are properly marked as peerDependencies
in package.json
. The rollup config will automatically recognize them as peers and not try to bundle them in your module.
I am looking for volunteers who would like to become active maintainers on the project. If you are interested, please shoot me a note.
FAQs
> CLI for creating reusable, modern Expo libraries using [Monorepo expo-yarn-workspaces](https://github.com/expo/expo/tree/master/packages/expo-yarn-workspaces) and expo init.
The npm package expo-library receives a total of 1 weekly downloads. As such, expo-library popularity was classified as not popular.
We found that expo-library demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.