
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
@indlekofer/media
Advanced tools
reducer for media related changes.
setup will be called at startup automaticaly (without force) and creates the store reducer. accepts one argument force (default true)
remove the reducer. for cleanup methods and testing
action with two arguments (key and value), no dispatch is needed
action with one argument (object of key values), no dispatch is needed
the actual injected reducers name
dispatched action type for handleChange
dispatched action type for handleChangeAll
FAQs
media
We found that @indlekofer/media demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.