
Security News
The Next Open Source Security Race: Triage at Machine Speed
Claude Opus 4.6 has uncovered more than 500 open source vulnerabilities, raising new considerations for disclosure, triage, and patching at scale.
sinamfe-webpack-module_dependency
Advanced tools
webpack 依赖树插件
一、 按照entry的dependencies递归查找 但是找dependencies时被扁平化了 例如 依赖关系: entry -> test-npm-module-react -> react @15.6.2 -> react @16.2.0
找entry的dependencies时,数组顺序 [ test-npm-module-react, react (@15.6.2), react (@16.2.0) ]
加了一层依赖深度的检测
二、 忽略了工程化本身的依赖
例如在entry的dependencies中可以找到两类依赖,除了工程本身的依赖还可以获取是webpack-marauder相关的公有依赖,可以找到promise-polyfill@6.1.0 object-assign@4.1.1。这类忽略掉了
三、 webpack-marauder升级可能会导致依赖树变化,需要对应检查
git add .
git cz
Run the npm version npm version [path|minor|major] command
//发小补丁
npm version patch -m 'commit message'
//发小版本
npm version minor -m 'commit message'
//发小版本
npm version major -m 'commit message'
cnpm publish
Push
git push
FAQs
We found that sinamfe-webpack-module_dependency demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Claude Opus 4.6 has uncovered more than 500 open source vulnerabilities, raising new considerations for disclosure, triage, and patching at scale.

Research
/Security News
Malicious dYdX client packages were published to npm and PyPI after a maintainer compromise, enabling wallet credential theft and remote code execution.

Security News
gem.coop is testing registry-level dependency cooldowns to limit exposure during the brief window when malicious gems are most likely to spread.