
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
@elemental-ui-alpha/radio
Advanced tools
The radio component is used in forms when a user may select a single value from several options.
import { Radio, RadioGroup, RadioPrimitive } from '@elemental-ui-alpha/radio';
Basic usage of radio.
<Radio defaultChecked>Uncontrolled</Radio>
<Stack gap="medium">
<Radio disabled>Disabled</Radio>
<Radio checked disabled>
Checked + Disabled
</Radio>
</Stack>
<Radio invalid checked={false}>
Invalid
</Radio>
<div style={{ width: 300 }}>
<Radio>
<>
Radio buttons can include <strong>bold text</strong> and{' '}
<a href="">anchors</a> which may wrap onto multiple lines.
</>
</Radio>
</div>
It's recommended to use the radio group component, which normalizes the
onChange and value behaviour.
Most of the time you'll only want the updated value, this is simplified by passing it back rather than the event. The original event is still available as the second argument if needed.
The checkbox group uses Stack under-the-hood so you can distribute each item
along the X or Y axis, using the direction prop:
vertical (default)horizontalconst [value, setValue] = React.useState('1');
const onChange = (val, event) => {
setValue(val);
console.log(event);
};
return (
<RadioGroup
direction="vertical"
legend="radio group"
onChange={onChange}
value={value}
>
<Radio value="1">First</Radio>
<Radio value="2">Second</Radio>
<Radio value="3">Third</Radio>
</RadioGroup>
);
For custom radio behaviours use the RadioPrimitive. This component isn't
already wrapped in a label, allowing full control of semantics and layout.
const [checked, setChecked] = React.useState([]);
const onChange = event => {
const item = event.target.value;
setChecked(item);
};
return (
<Columns gap="small" collapse="large">
{['First', 'Second', 'Third'].map(v => {
const isChecked = checked === v;
const bg = isChecked ? 'shade' : null;
return (
<Flex
align="center"
as="label"
background={bg}
direction="horizontal"
padding="small"
rounding="small"
>
<RadioPrimitive
key={v}
value={v}
checked={isChecked}
onChange={onChange}
/>
<Text marginLeft="small">{v}</Text>
</Flex>
);
})}
</Columns>
);
FAQs
The radio component is used in forms when a user may select a single value from several options.
We found that @elemental-ui-alpha/radio demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.