
Security News
Feross on TBPN: How North Korea Hijacked Axios
Socket CEO Feross Aboukhadijeh breaks down how North Korea hijacked Axios and what it means for the future of software supply chain security.
load-remote
Advanced tools
在 web 项目中引用载入远程资源(css, js),基于<link>/<script>标签实现。Used to load remote resources(CSS/JS) in a web project , based on the html tag(<link>/<script>).
pkg.module supported, which means that you can apply tree-shaking in you project
Used to load remote resources(CSS/JS) in a web project , based on the html tag(link/script).
https://github.com/livelybone/load-remote.git
https://github.com/livelybone/load-remote#readme
Your can see the usage by run the example of the module, here is the step:
git clone https://github.com/livelybone/load-remote.gitcd your-module-directorynpm i(use taobao registry: npm i --registry=http://registry.npm.taobao.org)npm run devhttp://127.0.0.1:3000/examples/test.html) in your browsernpm i -S load-remote
umd bundleLoadRemote
See what method or params you can use in index.d.ts
import * as LoadRemote from 'load-remote'
LoadRemote.loadRemote(
'https://cdn.jsdelivr.net/npm/pdfjs-dist@2.2.228/build/pdf.min.js',
{
injectParentElement: document.body,
},
).then(e => {
console.log(e.target)
// ... do the task after script loaded
const task = pdfjsLib.getDocument('./pdf-url.pdf')
task.promise.then(pdf => {
// ...
})
})
Use in html, see what your can use in CDN: unpkg
<-- use what you want -->
<script src="https://unpkg.com/load-remote/lib/umd/<--module-->.js"></script>
FAQs
在 web 项目中引用载入远程资源(css, js),基于<link>/<script>标签实现。Used to load remote resources(CSS/JS) in a web project , based on the html tag(<link>/<script>).
We found that load-remote demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Socket CEO Feross Aboukhadijeh breaks down how North Korea hijacked Axios and what it means for the future of software supply chain security.

Security News
OpenSSF has issued a high-severity advisory warning open source developers of an active Slack-based campaign using impersonation to deliver malware.

Research
/Security News
Malicious packages published to npm, PyPI, Go Modules, crates.io, and Packagist impersonate developer tooling to fetch staged malware, steal credentials and wallets, and enable remote access.