
Research
lightning PyPI Package Compromised in Supply Chain Attack
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.
postcss-mpvue-wxss
Advanced tools
PostCSS plugin for wxss.
专门为 wxss 格式化处理的的一个 postcss 插件,特别是在做 css 转 wxss 的时候好用到爆。
/* 被清理 */
* {
margin: 100px
}
/* 保持原样 */
view {
width: 50rpx;
}
.container {
width: 7.5rem;
font-size: .24rem
}
/* Web 标签转换 */
div {
width: 50rpx;
}
ul li {
width: 50rpx;
}
body {
width: 50rpx;
}
view {
width: 50rpx;
}
.container {
width: 50rpx;
font-size: 24.4rpx
}
._div {
width: 50rpx;
}
._ul ._li {
width: 50rpx;
}
page {
width: 50rpx;
}
postcss([ require('postcss-mpvue-wxss') ])
or use .postcssrc.js
// https://github.com/michael-ciniawsky/postcss-load-config
const optopns = {}
module.exports = {
"plugins": {
// to edit target browsers: use "browserslist" field in package.json
"postcss-mpvue-wxss": optopns
}
}
with options:
const replaceTagSelectorMap = require('postcss-mpvue-wxss/lib/wxmlTagMap')
const optopns = {
cleanSelector: ['*'],
remToRpx: 100,
replaceTagSelector: Object.assign(replaceTagSelectorMap, {
'*': 'view, text' // 将覆盖前面的 * 选择器被清理规则
})
}
更多详细文档请查阅 postcss-mpvue-wxss。
bug 或者交流建议等请反馈到 mpvue/issues。
See PostCSS docs for examples for your environment.
FAQs
PostCSS plugin for wxss
The npm package postcss-mpvue-wxss receives a total of 434 weekly downloads. As such, postcss-mpvue-wxss popularity was classified as not popular.
We found that postcss-mpvue-wxss demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.