
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
@pardjs/core
Advanced tools
Pardjs 是一套基于 nestjs 以及 dozto.com 开发中的最佳实践以及工程需要整理的一套开源组件,主要目的是提高代码的质量以及规范一些开发的常见功能方便协作。
📝:在计划任务中; 🚧:项目在开发中; ✅:已完成
资源模块用来处理常见的图片,视频,文件和静态页面发布的功能。目前实现基于阿里云的 OSS。
认证模块用来处理 Key Auth,Basic Auth,TOTP Auth,OAuth(微信登陆等),并关联必要的用户信息。
标签模块用来处理项目中需要处理标签和类别的相关信息。
FAQs
## 介绍
We found that @pardjs/core demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.