Security News
New Python Packaging Proposal Aims to Solve Phantom Dependency Problem with SBOMs
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.
TPM是前端打包工具。
源代码安装
git clone git://github.com/tudouui/tpm.git
NPM安装
npm install tpm -g
ytpm [command]
src/ # 源代码
js/
css/
img/
build/ # 打包后代码,未压缩
js/
css/
img/
dist/ # 压缩后代码
js/
css/
img/
project/ # 项目文件,用于批量操作
ytpm src/js/g.js
ytpm src/js/page/demo.js
ytpm src/js
ytpm src/css/g.less
ytpm src/css/page/demo.less
ytpm src/css
ytpm src/img/demo.png
ytpm src/embed/storage.html
ytpm src/img
ytpm project/TUILIB-65.txt
用config参数指定配置,默认用当前目录下的tpm-config.js
。
ytpm src/js/g.js --config=my-config.js
删除build、dist里的多余的目录和文件。
ytpm cleanup
FAQs
Static Package Manager
The npm package tpm receives a total of 5 weekly downloads. As such, tpm popularity was classified as not popular.
We found that tpm demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.
Security News
Socket CEO Feross Aboukhadijeh discusses open source security challenges, including zero-day attacks and supply chain risks, on the Cyber Security Council podcast.
Security News
Research
Socket researchers uncover how threat actors weaponize Out-of-Band Application Security Testing (OAST) techniques across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.