
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
竟然連 terminal 都開始業配了嗎? 可 ... 可惡!
在 iterm 上做全域安裝
$ npm i howhow -g
快來試試你的 how 手氣ㄅ~
$ howhow
每日一 how 就這樣產生了呢,用 Mac 的朋友加上 command 按鍵後 URL 就可以按了喔喔!
喔喔喔喔喔喔喔原來是旺梨小鎮的土鳳梨酥啊!
https://youtu.be/HM3PnOEJ1jI?t=30s
還可以從 terminal 直接進入業配頻道!男人就是要簡單!直白!
$ howhow open
什 ... 什麼? 竟然連 TED 都業配了 ... ?
$ howhow ted
進一步的相關操作可以在後頭加上 -h 參數
$ howhow -h
指示就會跳出~
howhow command line tool
Examples
$ howhow
喔喔喔喔喔喔喔原來是旺梨小鎮的土鳳梨酥啊!
https://youtu.be/HM3PnOEJ1jI?t=30s
Show version
$ howhow -v
version is 1.0.86
Open howhow youtube channel with Google Chrome
$ howhow open
See howhow on TED Talk
$ howhow ted
Source code of this side project
$ howhow github
MIT © WeiChiaChang
FAQs
howhow command line tool
The npm package howhow receives a total of 7 weekly downloads. As such, howhow popularity was classified as not popular.
We found that howhow demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.