
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
@jumplao/react-lz-editor
Advanced tools
An open source react editor based on draft-Js and ant design, good support HTML, markdown and Draft Raw format.
/**
* 感谢各位对本仓库的star和关注,以及提出的宝贵意见,万分抱歉没有及时跟进issue list,
* 本仓库最近着手使用ts进行重写,但会保持向下兼容,修复之前出现的问题,增加移动端适配等特性
*/
An open source react rich-text editor ( mordern react editor includes media support such as texts, images, videos, audios, links etc. ), development based on Draft-Js and Ant-design, good support html, markdown, draft-raw mode. It's supports multiple languages well and welcome you add your language supports.
| Li Zhen | Li Zhen | Boris Chernysh | SibaService.inc | Quốc Khánh | This JJ |
| English | Chinese (S. & T.) | Russian | Japanese | Vietnamese | Thai |
react-lz-editor: https://leejaen.github.io/react-lz-editor/index.html
Disabled media insert feature on demo page, because of there was no online API support for the time being, here is The server side API demo in java you may want.
npm install react-lz-editor --save
OR
yarn add react-lz-editor
Version note: React 15.4.2+ and react-dom 15.4.2+ is required. Antd version at least from 2.8.3 in your project is recommended.
git+ssh://git@github.com/leejaen/react-lz-editor.git
import React from 'react';
import ReactDOM from 'react-dom';
import LzEditor from './editor/index.jsx'
class Test extends React.Component {
constructor(props) {
super(props);
this.state = {
htmlContent: `<h1>Yankees, Peeking at the Red Sox, Will Soon Get an Eyeful</h1>
<p>Whenever Girardi stole a glance, there was rarely any good news for the Yankees. While Girardi’s charges were clawing their way to a split of their four-game series against the formidable Indians, the Boston Red Sox were plowing past the rebuilding Chicago White Sox, sweeping four games at Fenway Park.</p>`,
markdownContent: "## HEAD 2 \n markdown examples \n ``` welcome ```",
responseList: []
}
this.receiveHtml=this.receiveHtml.bind(this);
}
receiveHtml(content) {
console.log("recieved HTML content", content);
this.setState({responseList:[]});
}
render() {
let policy = "";
const uploadProps = {
action: "http://v0.api.upyun.com/devopee",
onChange: this.onChange,
listType: 'picture',
fileList: this.state.responseList,
data: (file) => {
},
multiple: true,
beforeUpload: this.beforeUpload,
showUploadList: true
}
return (
<div>
<div>Editor demo 1 (use default html format ):
</div>
<LzEditor active={true} importContent={this.state.htmlContent} cbReceiver={this.receiveHtml} uploadProps={uploadProps}
lang="en"/>
<br/>
<div>Editor demo 2 (use markdown format ):
</div>
<LzEditor
active={true}
importContent={this.state.markdownContent}
cbReceiver={this.receiveMarkdown}
image={false}
video={false}
audio={false}
convertFormat="markdown"/>
</div>
);
}
}
ReactDOM.render(
<Test/>, document.getElementById('test'));

| props | type | default | description |
|---|---|---|---|
| active | bool | false | Is reloading content after changing |
| importContent | string | "" | Editor content value, default to "" |
| lang | string | "" | Editor using language, default to your browser language settings |
| cbReceiver | function | null | Callback function, the changed value will be sent to its parameter. |
| undoRedo | bool | true | Enabled undo and redo feature, default to true |
| removeStyle | bool | true | Enabled remove style feature, default to true |
| pasteNoStyle | bool | true | Enabled paste plan text feature, default to true |
| blockStyle | bool | true | Enabled block style (H1,ol,pre etc.) feature, default to true |
| alignment | bool | true | Enabled text alignment feature, default to true |
| inlineStyle | bool | true | Enabled inline style (bold, italic, underline etc.) feature, default to true |
| color | bool | true | Enabled color text feature, default to true |
| image | bool | true | Enabled insert image feature, default to true |
| video | bool | true | Enabled insert video feature, default to true |
| audio | bool | true | Enabled insert audio feature, default to true |
| urls | bool | true | Enabled add hyper link feature, default to true |
| autoSave | bool | true | Enabled auto save to draft-box feature, default to true |
| fullScreen | bool | true | Enabled full screen feature, default to true |
| convertFormat | string | "html" | Set support format (html, markdown, raw), default to "html" |
| disabled | bool | false | Disabled editor or not |
| uploadProps | object | null | Customize uploading settings. API: Antd.Upload |
FAQs
An open source react editor based on draft-Js and ant design, good support HTML, markdown and Draft Raw format.
We found that @jumplao/react-lz-editor demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.