
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
信息熵,使用 TypeScript 实现。
在机器学习中,熵刻画了任意样例集的纯度。给定包含关于某个目标概念的正反样例的样例集 S,那么 S 相对这个布尔型分类的熵为:
Entropy(S) = -p+log2(p+) - p-log2(p-)
其中,p+是在 S 中正例的比例,p-是在 S 中反例的比例。在有关熵的所有计算中我们定义 0log0 为 0。
npm install entropy-ts
import { entropy } from 'entropy-ts'
const samples = [
'+', '+', '-', '+', '-', '-'
]
const res = entropy(samples)
assert.deepStrictEqual(res, 1)
修改代码后跑
npm test
确保测试通过。
git commit
npm version patch/minor/major
npm publish
FAQs
We found that entropy-ts demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.