Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Tree view for your demo components. Demo.
npm install -D vue-book
yarn add -D vue-book
I'll talk a bit about demo based workflow I employ in my projects.
Before doing any work on component I create a demo. Demo allows me to define an interface, like this:
<my-new-component v-model="dataItem" :some-prop="prop"/>
Only then I start to work on component.
You can think of demo as of semi-manual unit tests. But why not use actual unit tests, you'll ask. Let me explain.
Of course, this doesn't mean that you have to dump unit tests. Just keep them for appropriate tasks. Like logic heavy classes.
So, back to the library. The main intent behind is simplifying demo workflow as much as possible. Just toss your demos into folder and enjoy tree generation.
Attach VueComponentTree to your router. And yes, vue-router is required.
import Router from 'vue-router'
import VueBook from 'vue-book'
const router = new Router({
routes: [
VueBook(require.context('./../tree', true, /.vue$/), '/demo'),
]
})
So, about arguments.
require.context('./../tree', true, /.vue$/), '/demo'
./../tree
is path to your demo folder. Works the same as require/import./demo
is root route for vue-router.You don't have to keep demos in production. Use webpack define-plugin and exclude them from bundle.
if (process.env.NODE_ENV !== 'production') {
const VueBook = require('vue-book').default
routes.push({
path: '/demo',
component: App,
children: [
VueBook(require.context('./..', true, /.demo.vue$/), '/demo'),
],
})
}
yarn serve
- run dev server;yarn demo
- compile assets;yarn dist
- compile assets;npm publish
- publish to npm.Leave an issue if something doesn't work for you.
Also remember: Stars fuel package development!
MIT
FAQs
Tree view for your demo components
The npm package vue-book receives a total of 49 weekly downloads. As such, vue-book popularity was classified as not popular.
We found that vue-book demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.