
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
A tool to help you quickly create file in project
npm i mkfile-cli
添加mk.json在项目的根目录,配置mk.json,dir为生成目标文件的路径,js为文件后缀名,tpl是文件模板路径。模板内容可以自定义,使用的模板语法是nunjucks。
{
"fileList" : [
{"dir": "test/js", "suffix": "js", "tpl": "tpl/js.tpl"},
{"dir": "test/css", "suffix": "css", "tpl": "tpl/css.tpl"}
],
"activityList" : [
{"dir": "activity/js", "suffix": "js", "tpl": "tpl/js.tpl"}
]
}
mk --new [filename] --key [keyname]
mk -n [filename] -k [keyname]
keyname对应mk.json中的key值,若不传,则默认为fileList。
mk --new hellomk会根据模板创建文件test/js/hellomk.js和test/css/hellomk.css,若无tpl参数,则创建空文件;mk --new hellomk --key activityList会根据模板创建文件activity/js/hellomk.jsFAQs
A tool to help you quickly create file in project
The npm package mkfile-cli receives a total of 1 weekly downloads. As such, mkfile-cli popularity was classified as not popular.
We found that mkfile-cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.