跳到主要内容
知仓学习社ZHICANG

antfu

Anthony Fu's opinionated tooling and conventions for JavaScript/TypeScript projects. Use when setting up new projects, configuring ESLint/Prettier a…

读凭据写文件严重 1 · 高危 2JetBrains/skills

它会碰到什么

扫了多少6 个文本文件,17 KB
它会碰到什么读凭据写文件
命中总数5 处
命中统计严重 1 · 高 2 · 中 0 · 低 0
逐条看命中(3 条严重或高危)
  • 严重 references/setting-up.md:18cred-paths
    .idea
  • references/antfu-eslint-config.md:237identity-config-write
    "simple-git-hooks": {
  • SKILL.md:99identity-config-write
    "simple-git-hooks": {

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Coding Practices

Code Organization

  • Single responsibility: Each source file should have a clear, focused scope/purpose
  • Split large files: Break files when they become large or handle too many concerns
  • Type separation: Always separate types and interfaces into types.ts or types/*.ts
  • Constants extraction: Move constants to a dedicated constants.ts file

Runtime Environment

  • Prefer isomorphic code: Write runtime-agnostic code that works in Node, browser, and workers whenever possible
  • Clear runtime indicators: When code is environment-specific, add a comment at the top of the file:
// @env node
// @env browser

TypeScript

  • Explicit return types: Declare return types explicitly when possible
  • Avoid complex inline types: Extract complex types into dedicated type or interface declarations

Comments

  • Avoid unnecessary comments: Code should be self-explanatory
  • Explain "why" not "how": Comments should describe the reasoning or intent, not what the code does

Testing (Vitest)

  • Test files: foo.tsfoo.test.ts (same directory)
  • Use describe/it API (not test)
  • Use toMatchSnapshot for complex outputs
  • Use toMatchFileSnapshot with explicit path for language-specific snapshots

Tooling Choices

@antfu/ni Commands

| Command | Description |

|---------|-------------|

| ni | Install dependencies |

| ni <pkg> / ni -D <pkg> | Add dependency / dev dependency |

| nr <script> | Run script |

| nu | Upgrade dependencies |

| nun <pkg> | Uninstall dependency |

| nci | Clean install (pnpm i --frozen-lockfile) |

| nlx <pkg> | Execute package (npx) |

TypeScript Config

{
  "compilerOptions": {
    "target": "ESNext",
    "module": "ESNext",
    "moduleResolution": "bundler",
    "strict": true,
    "esModuleInterop": true,
    "skipLibCheck": true,
    "resolveJsonModule": true,
    "isolatedModules": true,
    "noEmit": true
  }
}

ESLint Setup

// eslint.config.mjs
import antfu from '@antfu/eslint-config'

export default antfu()

When completing tasks, run pnpm run lint --fix to format the code and fix coding style.

For detailed configuration options: [antfu-eslint-config](references/antfu-eslint-config.md)

Git Hooks

{
  "simple-git-hooks": {
    "pre-commit": "pnpm i --frozen-lockfile --ignore-scripts --offline && npx lint-staged"
  },
  "lint-staged": { "*": "eslint --fix" },
  "scripts": {
    "prepare": "npx simple-git-hooks"
  }
}

pnpm Catalogs

Use named catalogs in pnpm-workspace.yaml for version management:

| Catalog | Purpose |

|---------|---------|

| prod | Production dependencies |

| inlined | Bundler-inlined dependencies |

| dev | Dev tools (linter, bundler, testing) |

| frontend | Frontend libraries |

Avoid the default catalog. Catalog names can be adjusted per project needs.


References

| Topic | Description | Reference |

|-------|-------------|-----------|

| ESLint Config | Framework support, formatters, rule overrides, VS Code settings | [antfu-eslint-config](references/antfu-eslint-config.md) |

| Project Setup | .gitignore, GitHub Actions, VS Code extensions | [setting-up](references/setting-up.md) |

| App Development | Vue/Nuxt/UnoCSS conventions and patterns | [app-development](references/app-development.md) |

| Library Development | tsdown bundling, pure ESM publishing | [library-development](references/library-development.md) |

| Monorepo | pnpm workspaces, centralized alias, Turborepo | [monorepo](references/monorepo.md) |

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。