
Research
/Security News
Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages
Miasma Mini Shai-Hulud hits @immobiliarelabs Backstage plugins, targeting GitLab and LDAP auth packages on npm.
这是一个用于从 'package-lock.json' 或者 'yarn.lock' 文件中提取并下载 '.tgz' 依赖包的命令行工具。
npm install -g picktgz
picktgz [package-lock.json] [--add-sh]
如果没有指定 'package-lock.json' 文件路径,将默认使用当前目录下的 'package-lock.json' 文件。 使用 '--add-sh' 选项可以将名为 'npmPublish.sh' 的脚本复制到 'modulestgz' 文件夹中。
picktgz
picktgz /path/to/package-lock.json
picktgz --add-sh
如果您在使用 'picktgz' 时遇到问题或需要帮助,请提交 issue 到我们的 GitHub 仓库。
FAQs
Download tgz files from package-lock.json or yarn.lock
The npm package picktgz receives a total of 1 weekly downloads. As such, picktgz popularity was classified as not popular.
We found that picktgz demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Miasma Mini Shai-Hulud hits @immobiliarelabs Backstage plugins, targeting GitLab and LDAP auth packages on npm.

Security News
Rolldown paused Rust React Compiler integration after a 5MB binary size increase raised concerns about shipping React-specific code to all Vite users.

Security News
/Research
Mini Shai-Hulud expands into the Go ecosystem after hitting LeoPlatform npm packages and targeting GitHub Actions workflows.