
Research
/Security News
Popular Tinycolor npm Package Compromised in Supply Chain Attack Affecting 40+ Packages
Malicious update to @ctrl/tinycolor on npm is part of a supply-chain attack hitting 40+ packages across maintainers
terminal-dict
Advanced tools
程序员懒人福利,不用切换命令行,直接在命令行里查词。
模板: 不同种类的词典(eg: 英汉、网络释义、例句等等)
第一种查词方式:是可查询指定模板的内容
第二种查词方式:是查询所有模板
npm install terminal-dict -g
yd --help //查询当前支持的模板都有哪些
yd good //查询good这个单词 (默认显示英汉模板)
yd good web_trans //查找good这个单词的网络释义模板(第二个参数指定特定模板)
yd good --all //查找good这个单词的所有模板
FAQs
terminal-dict
The npm package terminal-dict receives a total of 1 weekly downloads. As such, terminal-dict popularity was classified as not popular.
We found that terminal-dict demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Malicious update to @ctrl/tinycolor on npm is part of a supply-chain attack hitting 40+ packages across maintainers
Security News
pnpm's new minimumReleaseAge setting delays package updates to prevent supply chain attacks, with other tools like Taze and NCU following suit.
Security News
The Rust Security Response WG is warning of phishing emails from rustfoundation.dev targeting crates.io users.