Secure your dependencies. Ship with confidence.Socket is a developer-first security platform that protects your code from both vulnerable and malicious dependencies.
ã¯ããã«@typesã¹ã³ã¼ãã管çãã¦ããDefinitely Typedã¯ãMicrosoftããæ¯æ´ãåãã¦ãããã®ã®ãMicrosoftã®èå¼±æ§å ±å¥¨éå¶åº¦ã«ãããã»ã¼ããã¼ãã¼ã®å¯¾è±¡ã§ã¯ããã¾ããã1 æ¬è¨äºã¯ãå ¬éããã¦ããæ å ±ãå ã«èå¼±æ§ã®åå¨ãæ¨æ¸¬ããå®éã«æ¤è¨¼ãããã¨ãªãæ½å¨çãªèå¼±æ§ã¨ãã¦å ±åããåé¡ã«é¢ãã¦èª¬æãããã®ã§ãããç¡è¨±å¯ã®èå¼±æ§è¨ºæè¡çºãæ¨å¥¨ãããã¨ãæå³ãããã®ã§ã¯ããã¾ããã Definitely Typedã«èå¼±æ§ãçºè¦ããå ´åã¯ãDefinitely Typedã®ã¡ã³ãã¼ã¸å ±åãã¦ãã ããã è¦ç´Definitely Typedã®ãã«ãªã¯ã¨ã¹ã管çBotã«èå¼±æ§ãåå¨ããæªæã®ãããã«ãªã¯ã¨ã¹ããDefinitelyTyped/DefinitelyTypedãªãã¸ããªã¸ãã¼ã¸ãããã¨ãå¯è½ã ã£ãã ããã«ãããnpmä¸ã®@typesã¹ã³ã¼ãé ä¸ã«åå¨ã
ããã³ãã¨ã³ãã¨ãã¹ãã¼ããã¼ã ã®å°æ(@koba04)ã§ãã å æ¥ãnpmããèå¼±æ§ã«ã¤ãã¦ã®çºè¡¨ãããã¾ããã 調ã¹ã¦ããä¸ã§ããã¤ãæãã¨ããããã£ãã®ã§è§£èª¬ãå ¼ãã¦æ¸ãã¦ããããã¨æãã¾ãã The npm Blog â Binary Planting with the npm CLI npmã®å©ç¨è ã¨ãã¦ããã¹ããã¨ã¯ã npmã®ãã¼ã¸ã§ã³ã6.13.4以ä¸ã«ããã yarnã®ãã¼ã¸ã§ã³ã1.21.1以ä¸ã«ããã ã§ãã npmã®ãã¼ã¸ã§ã³ã6.13.4ã«ãªã£ãNodeãv8, v10, v12, v13ç³»ã§ãããããªãªã¼ã¹ãããã®ã§ããã¡ããå©ç¨ãããã¨ãå¯è½ã§ã ï¼yarnã®ãã¼ã¸ã§ã³ã¯å¥éãããå¿ è¦ãããã¾ãï¼ã nodejs.org npmã«ããçºè¡¨ã§ã¯ãä»åçºè¡¨ãããèå¼±æ§ã¯2件ãããããããããåå¥ã«èãã¾ãã binã«ä»»æã®ãã¹ãæå®åºæ¥ã件 npmããã±ã¼ã¸ã¯pa
The npm blog has been discontinued. Updates from the npm team are now published on the GitHub Blog and the GitHub Changelog. Last month, we announced npm@6, which includes a powerful new tool to protect the safety of your code, npm audit. Together with new automatic alerts when a user installs code with a known security risk, audit is a dramatic step to ensure the quality and integrity of the code
The npm blog has been discontinued. Updates from the npm team are now published on the GitHub Blog and the GitHub Changelog. On August 1, a user notified us via Twitter that a package with a name very similar to the popular cross-env package was sending environment variables from its installation context out to npm.hacktask.net. We investigated this report immediately and took action to remove the
Malicious packages in npm. Hereâs what to do | Ivan Akulovâs blog People found malicious packages in npm that work like real ones, are named similarly real ones, but collect and send your process environment to a third-party server when you install them 訳: æªæã®ããããã±ã¼ã¸ãnpmã§çºè¦ãããããããã¯ãå®éã®ããã±ã¼ã¸ã«ããä¼¼ãååã§åãããã«åãããããã±ã¼ã¸ã®ã¤ã³ã¹ãã¼ã«æã«ããã»ã¹ã®ç°å¢å¤æ°ãå¤é¨ã®ãµã¼ãã«éä¿¡ããã çºè¦ãããããã±ã¼ã¸ã®ä¸è¦§ã¯å ã¨ã³ããªãã©ããããã®ãããªãã«ã¦ã§ã¢ã§ããå½ããã±ã¼ã¸ã®ä¸ä¾ããããã¨ã ba
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}