
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
一个快速上手的前端脚手架, 轻松创建项目模板, 实现0配置, 快速开发。
Windows系统安装
$ npm i easy-tool-cli -g
Mac下安装
$ sudo npm i easy-tool-cli -g
$ easy
# 指定项目名字创建项目
$ easy create 模板名<template-name> 项目名字<project-name>
# 在当前目录创建项目
$ easy create 模板名<template-name> .
$ easy list
$ easy add 模板名<template-name> 模板github仓库地址,支持ssh/https格式<git-repo-address>
$ easy delete 模板名<template-name>
执行pkg下的脚本, 自动发版并且生成changelog, travis就会执行检测后续自动发到npm.
npm run release
FAQs
a simple CLI for scaffolding of FE
The npm package nanny-cli receives a total of 1 weekly downloads. As such, nanny-cli popularity was classified as not popular.
We found that nanny-cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.