
Security News
npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders
npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback.
festaticcompress 是一个压缩javascript, css,image的工具。
First make sure you have installed the latest version of node.js (You may need to restart your computer after this step).
From NPM for use as a command line app: npm install festaticcompress -g
From NPM for programmatic use: npm install festaticcompress
From Git:
git clone git://github.com/festaticcompress/festaticcompress.git
cd festaticcompress
npm link .
Usage: festaticcompress
Commands: "all" 递归压缩图片,js,css Options: -p, --path 资源路径 -h, --help help
For example: festaticcompress all -p ./ 压缩当前目录下的所有静态资源
festaticcompress all -p "/path" 压缩"path"路径下的所有静态资源
FAQs
festaticcompress
The npm package wangliming receives a total of 4 weekly downloads. As such, wangliming popularity was classified as not popular.
We found that wangliming demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback.

Research
/Security News
Newer packages in this compromise use native extensions and .pth loaders to execute JavaScript stealers in developer environments.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.