
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
#newcli
初始化自定义脚手架 ##安装
npm i [-g] newcli
##初始化 选项:
[ -h ] & &//帮助选项 [ -m ] & &//|| 切换脚手架,默认执行第一个项目,查看项目请使用【ls】选项 [ add ] & &// 添加依赖包,以空格隔开,其中选项参数【-m 】,添加当前项目包的名称与描述,参数可选 [ ls ] & &//查看现有所有项目包 [ rm ] & &//||<@projectNumber> 删除项目,其中选项参数【-all】,删除所有项目
newcli [init/new] <dirName>
##示例
配置脚手架项目包
//添加项目依赖包
newcli config add jquery
.....
//添加项目依赖包并添加名称以及项目包说明
newcli config add jquery -m jquery 这是一款非优秀的DOM操作的javascript库。
//查看所有项目依赖包
newcli config ls
//删除项目依赖包
newcli config rm jquery
//删除所有项目依赖包
newcli config rm -all
//切换项目包
newcli config -m jquery
创建脚手架
//初始化myApp项目
newcli init
//初始化并自定义test项目
newcli init test
//新建test1项目
newcli new test1
FAQs
We found that newcli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.