#npmjs — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #npmjs, aggregated by home.social.
-
«Passwortsafe Bitwarden — Kommandozeilen-Client trojanisiert:
Das Bitwarden-Security-Team bestätigt, dass kurzzeitig eine bösartige Version des Kommandozeilen-Client ausgeliefert wurde.»Jetzt war @bitwarden daran und das per NPM. Wieviel mal wird dies und ähnliches noch auftauchen? NPM ist leider mittlerweile das Einfallstor für viele Sicherheitslücken.
🔐 https://www.heise.de/news/Passwortsafe-Bitwarden-Kommandozeilen-Client-trojanisiert-11270435.html
#npm #bitwarden #javascript #hacking #passwort #js #npmjs #itsicherheit #it #web #webdev #sicherheit
-
I'm having issues with build tooling, so needing to do slash and burn dev development.
Have #MSFT deployed a rate limitor on #NPMJS? I have only deployed ~ 400 packages *today* to a single IP, so i should be inside reasonable usage.
My package-lock say packages are installed, but the files aren't present.I would be downloading less packages if I have a way to remove dev-dep without `rm-rf`
-
I'm having issues with build tooling, so needing to do slash and burn dev development.
Have #MSFT deployed a rate limitor on #NPMJS? I have only deployed ~ 400 packages *today* to a single IP, so i should be inside reasonable usage.
My package-lock say packages are installed, but the files aren't present.I would be downloading less packages if I have a way to remove dev-dep without `rm-rf`
-
Guys!
If you want to make a #crossplatform #app, and you don't know what's framework should I use?
Just use #Tauri and don't waste your time on #electronjs, #flatten or other stuff.
Tauri is light and too easy.
Check out the Tauri site:
#rust #rustlang #javascript #typescript #npmjs #npm #cargo #programming #program #code #hacker #hack #gui #uidesign #ui #uxdesign #ux
https://tauri.app/ -
Totally unrelated: I wonder how many people using libheif-js through heic-decode and heic-convert on #npmjs are actually violating #libheif's license, because heic-decode and heic-convert are not LGPL licensed even though libheif-js is, and most people probably use them without digging through the licenses of the dependencies.
-
@Perl There’s something to be said for putting a small speed bump in front of #developers before they can post #software to a well-indexed central repository: “One In Two New #npm Packages Is #SEO #Spam Right Now” https://blog.sandworm.dev/one-in-two-new-npm-packages-is-seo-spam-right-now
How to start with #Perl’s #CPAN via #PAUSE:
1) Read https://www.cpan.org/modules/04pause.html
2) Visit https://pause.perl.org