
Research
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
基于本工程,您可以构建属于自己的跨技术栈/无框架 组件。
pnpm install
pnpm run dev
入口文件为 src/index.tsx,这里使用 vite 进行开发和生产打包。
pnpm run build
打包后的产出为: lib/index.js和lib/index.umd.cjs。
.
├── types
| └── install.d.ts
├── index.js
└── index.umd.js
无论是Vue,React,Angular还是Jq项目,该组件都可以被使用。
import "my-component/lib";
<my-component count="0" />;
详细文档,请访问:https://quarkc.hellobike.com/#/zh-CN/docs/publishing
FAQs
基于本工程,您可以构建属于自己的跨技术栈/无框架 组件。
The npm package hdg-design receives a total of 2 weekly downloads. As such, hdg-design popularity was classified as not popular.
We found that hdg-design demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.

Security News
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.