
Security News
npm ‘is’ Package Hijacked in Expanding Supply Chain Attack
The ongoing npm phishing campaign escalates as attackers hijack the popular 'is' package, embedding malware in multiple versions.
Simplify management of local npm and node.js development resources and processes, such as symlinks, global dependencies, etc. It's like grunt or gulp, but with 100x less code and a flatter learning curve.
Simplify management of local npm and node.js development resources and processes. Add stuff to your package.json
and watch it work. It's like grunt or gulp, but with 100x less code and a flatter learning curve. It is a pure essentialization of the "task-runner", and is designed to be magical, but not mysterious. nex
is un-opinionated, npm-integrated, and fully-discombobulated.
$ npm install -g nex
nex
array to define the general order of executionnex do
will do all the things in this array.
package.json:
{
"nex": [
"repository",
"engines",
"globalDependencies",
"linkDependencies"
]
}
npm
phases you want nex
to controlpackage.json:
{
"scripts": {
"preinstall": "nex do",
"pretest": "nex do engines"
}
}
nex
operates by declarative fiat. There's no special build file to contstruct, environment to define, or configs to set. Your existing package.json declares which nex
routines run during each npm
phase.
nex
routinesrepository
(npm)$ nex do repository
Use this when you want to download and extract this module from the repository defined in the repository
field. Useful for hosting Github-authenticated private modules publicly on npmjs.org. If the module is private, you'll be prompted for your Github credentials.
package.json:
{
"license": "Proprietary",
"repository": {
"type": "git",
"url": "git://github.com/tjwebb/super-nex.git",
"private": true
}
}
.npmignore
index.js
lib/
private-stuff/
globalDependencies
(npm)$ nex do globalDependencies
Install dependencies globally, automatically as part of npm's normal installation process.
package.json
{
"globalDependencies": {
"<module>": "<version>",
"jshint": "^2.5"
}
}
linkDependencies
(npm)$ nex do linkDependencies
Create symlinks from node_modules/<module>
to <path>
package.json
{
"linkDependencies": {
"<module>": "<path>",
"module1": "./lib/module1"
}
}
symlinks
(npm)$ nex do symlinks
Create arbitrary <link>
to any <target>
package.json
{
"symlinks": {
"<target>": "<link">,
"./lib/shared.js": "/usr/share/superlib/shared.js"
}
}
engines
(npm)$ nex do engines
Ensure that all npm commands are invoked with the correct version of node as defined in the standard engines
field
package.json
{
"engines": {
"node": "^0.11.13"
}
}
nex
yourselfAnyone can extend nex. Create a node module that exposes the methods do
and undo
, name it after the package.json field you want to operate on, and publish it to npmjs.org as nex-<field>
.
do (package)
@param package {Object} package.json object
undo (package)
@param package {Object} package.json object
FAQs
Simplify management of local npm and node.js development resources and processes, such as symlinks, global dependencies, etc. It's like grunt or gulp, but with 100x less code and a flatter learning curve.
The npm package nex receives a total of 83 weekly downloads. As such, nex popularity was classified as not popular.
We found that nex demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
The ongoing npm phishing campaign escalates as attackers hijack the popular 'is' package, embedding malware in multiple versions.
Security News
A critical flaw in the popular npm form-data package could allow HTTP parameter pollution, affecting millions of projects until patched versions are adopted.
Security News
Bun 1.2.19 introduces isolated installs for smoother monorepo workflows, along with performance boosts, new tooling, and key compatibility fixes.