
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
如果说组件是没有生命的驱壳,数据则是灵魂,而我们想要创造的是拥有灵魂的“精灵”。
Zero UI为Vert.x Zero Up Framework的前端脚手架,主要用于和Vert.x Zero Up微服务框架后端进行配合开发,该前端脚手架主要内容如下:
该项目中使用了两个项目作为参考Demo,一个项目为通用企业项目,另外一个项目则是Zero Up Framework的后端监控框架,统一采用Zero UI来完成,官方网址:
依赖库固定版本(升级后有兼容性问题)
| 库名称 | 当前版本 | 最新版 |
|---|---|---|
| rxjs | 5.5.10 | 6.1.0 |
| webpack | 3.11.0 | 4.6.0 |
| webpack-dev-server | 3.0.0 | 3.1.4 |
| awesome-typescript-loader | 4.0.1 | 5.0.0 |
文档基本前缀说明。
UI文档为开发文档,提供给开发人员使用来开发项目专用;UT文档为研发文档,提供给研发人员开发Zero UI专用;整个Zero框架的结构图如下:

参考UT0001,运行脚本run-doc.sh,则可以从浏览器查看文档:http://localhost:5000/
FAQs
> _如果说组件是没有生命的驱壳,数据则是灵魂,而我们想要创造的是拥有灵魂的“精灵”。_
We found that zero-i demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.