
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
Props属性如下
| props | 说明 | 类型 | 默认值 | 备选 |
|---|---|---|---|---|
| columns | 列的定义 | array | [] | |
| rows | 数据列表 | array | [] | |
| offset | 分页码、不设置相关属性则不会产生分页组件 | number | -1 | |
| total | 总页数 | number | 0 | |
| limit | 每页数量 | number | 20 | |
| renderKey | key,需要自定义绑定到一个key,如果数据没有唯一的key,将会自定采用index | string | ||
| enableSelection | 使用全选功能 | boolean | false | |
| className | 自定义容器的类名 | string | table-responsive | |
| heightControl | 高度限制 | string | ‘’ | |
| TableStyle | 表格风格 | array | ['bordered'] | bordered\triped\condensed |
| myHeadStyle | 表格头风格 | string | active | active\success\info\warning\danger |
| batch | 自定义绑定多选功能的按钮 | array | [] |
每一行都可以单独设定divStyle、className, className可以直接传递字符串
每一单元格可以单独设定divStyle、className、orderBy、renderer
行的回调参数是line info
单元格的回调参数分别是value line info
FAQs
## 功能
We found that cat-grid demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.