
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
A simple file watcher that clears the console and runs flow on each change. Currently tested on OS X -- I don't know
if it works on Linux or Windows. Works with flow on your path or flow-bin installed as a peer dependency.
npm install --save-dev flow-watch
Then run the flow-watch command.
flow-watch passes known nodemon options to nodemon, and all other options
to flow.
nodemon has a documented way to clear the console on restart, so you may want to use nodemon/flow directly
in a package script instead of using flow-watch.
flow-watch uses nodemon and accepts any command-line options that nodemon does.
If you provide no arguments, it uses the following defaults:
--ignore node_modules/ --watch *.js --watch *.jsx --watch *.js.flow --watch .flowconfig
By default, the watcher will clear the console between each change. If you wish to override this behavior, use the FLOW_WATCH_NO_CLEAR_CONSOLE env variable. If you choose that approach, you may also want to silent the [nodemon] messages in the console, which you can do with the --quiet flag (or -q). Putting it all together:
{
"scripts": {
"flow:watch": "FLOW_WATCH_NO_CLEAR_CONSOLE=1 flow-watch -q"
}
}
FAQs
clear the console and run flow on file changes
The npm package flow-watch receives a total of 1,640 weekly downloads. As such, flow-watch popularity was classified as popular.
We found that flow-watch demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.