
Research
/Security News
Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets
Attackers compromised Trivy GitHub Actions by force-updating tags to deliver malware, exposing CI/CD secrets across affected pipelines.
@nivo/line
Advanced tools
Recharts is a composable charting library built on React components. It provides a wide range of chart types, including line charts, and is known for its simplicity and ease of use. Compared to @nivo/line, Recharts offers a more straightforward API but may lack some of the advanced customization options available in @nivo/line.
Victory is a modular charting library for React and React Native. It offers a variety of chart types, including line charts, and is designed to be highly customizable and extensible. Victory is comparable to @nivo/line in terms of flexibility and customization, but it may require more configuration to achieve similar results.
Chart.js is a popular JavaScript library for creating simple yet flexible charts. It can be used with React through various wrappers like 'react-chartjs-2'. While Chart.js provides a robust set of features for line charts, it is not as tightly integrated with React as @nivo/line, which may result in a less seamless development experience.
FAQs
Unknown package
The npm package @nivo/line receives a total of 307,689 weekly downloads. As such, @nivo/line popularity was classified as popular.
We found that @nivo/line demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Attackers compromised Trivy GitHub Actions by force-updating tags to deliver malware, exposing CI/CD secrets across affected pipelines.

Security News
ENISA’s new package manager advisory outlines the dependency security practices companies will need to demonstrate as the EU’s Cyber Resilience Act begins enforcing software supply chain requirements.

Research
/Security News
We identified over 20 additional malicious extensions, along with over 20 related sleeper extensions, some of which have already been weaponized.