
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
chika-component
Advanced tools
暴露作者资浅水准的一系列山寨组件,你会发现里面有各种组件库的影子,就好像作者的人生一样
online demo: https://zy410419243.github.io/chika-component/#/container
“哇,这个轮子造的好屌,麻麻我也想造一个!”
“什么,居然还有这么符合朕性癖的轮子?”
“我有轮子,给。”说着他们递过来一架纯金打造的赛车
“这尼玛是轮子?” 我左看右看,歪歪斜斜每个 index 里都写着规范两个字。我横竖睡不着,仔细看了半夜,才从 component 里看出字来,整整一个 repo 都写着两个字是冗余
“拆下来就是了。”他们用莫名热切的目光看着我
“欸等等...你这轱辘好像不圆。”
西方哪个 repo 我没见过,造个轮子不是轻松得 彳...
FAQs
A react-component collection, IQ3 でもまかせなさいー!
We found that chika-component demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.