
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
qiankun-vue-template
Advanced tools
A full-featured Webpack setup with hot-reload, lint-on-save, unit testing & css extraction.
This template is Vue 2.0 compatible. For Vue 1.x use this command:
vue init webpack#1.0 my-project
This template was the main template for vue-cli verison 2.*.
Now that we have released a stable version of vue-cli 3, which incorporates all features that this template offers (and much more), we think that this template doesn't have any significant use for the future, so we won't put much resource in developing it further.
We will try and fix major issues should they arise, but not much more.
Feel free to fork this template if you want to keep it alive.
This is a project template for vue-cli. It is recommended to use npm 3+ for a more efficient dependency tree.
$ npm install -g vue-cli
$ vue init webpack my-project
$ cd my-project
$ npm install
$ npm run dev
This will scaffold the project using the master branch. If you wish to use the latest version of the webpack template, do the following instead:
$ vue init webpack#develop my-project
:warning: The develop branch is not considered stable and can contain bugs or not build at all, so use at your own risk.
The development server will run on port 8080 by default. If that port is already in use on your machine, the next free port will be used.
npm run dev: first-in-class development experience.
vue-loader for single file Vue components.npm run build: Production ready build.
index.html with proper URLs to these generated assets.npm run build --reportto build with bundle size analytics.npm run unit: Unit tests run in JSDOM with Jest, or in PhantomJS with Karma + Mocha + karma-webpack.
npm run e2e: End-to-end tests with Nightwatch.
You can fork this repo to create your own boilerplate, and use it with vue-cli:
vue init username/repo my-project
FAQs
Customized qiankun micro application template
We found that qiankun-vue-template demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.