
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
A workshopper that teaches you about choo.
You need the latest stable Node.js release to run this workshopper!
npm install -g choo-choo
Then, just run choo-choo, select the first exercise, and you're good to go!
This workshopper is in active development. There's currently only a couple of exercises, but we're working on pushing out more. If you want to help out, have a look at how to contribute!
In order to get a basic local setup:
git clone https://github.com/choojs/choo-choo
cd choo-choo
npm install
It's recommended that you run npm link so that you can use the choo-choo
command globally, but still symlinked to your development folder. This makes
testing exercises much easier.
npm test: runs the standard style linter<olivia@fastmail.com>GNU AGPL 3, see LICENSE
FAQs
learn choo on the terminal!
We found that choo-choo demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.