
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
这是一个准备发布到UNPKG的Web应用程序。
<!-- 直接访问主页 -->
https://unpkg.com/d0051s@latest/
<!-- 或者引用特定文件 -->
https://unpkg.com/d0051s@latest/index.html
<!-- 访问静态资源 -->
https://unpkg.com/d0051s@latest/static/images/4-001.png
https://unpkg.com/d0051s@latest/static/css/base.css
index.htmlindex.htmlup/
├── index.html # 主入口文件
├── package.json # NPM包配置
├── static/ # 静态资源
│ ├── css/ # 样式文件
│ ├── js/ # JavaScript文件
│ ├── images/ # 图片资源
│ └── fonts/ # 字体文件
├── assets/ # 其他资源文件
└── pages/ # 页面相关资源
MIT
FAQs
A web application for UNPKG distribution
We found that d0051ss demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.