
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
Nuz is a fancy library to implements Micro Frontends compatible with ReactJS and may support more in the future
Nuz is a fancy library to implements Micro Frontends compatible with ReactJS and may support more in the future. 🏃
The idea behind Micro Frontends is to think about a website or web app as a composition of features which are owned by independent teams. Each team has a distinct area of business or mission it cares about and specialises in. A team is cross functional and develops its features end-to-end, from database to user interface.
from micro-frontends.org
Micro-frontends is a microservice-like architecture that applies the concept of microservices to the browser side. Transforming to a mono-like applications from a single, single application to an application that combines multiple small front-end applications. Each frontend application can also be standalone run, independent development, standalone deployment.
from a post in dev.to
But you can think easier like... You can use Micro Frontends to building modern web apps with multiple teams, such as e-commerce, social network...
I found some articles about it
Yep, it really hard but... I created Nuz to help you! 😉
Nooo, you can use Nuz with your React application, Nuz is compatible with the projects created by create-next-app and create-react-app.
Nuz just is something great to resolve the problems while implements Micro Frontends application such as:
require by resolve.express.webpack config.And other packages just create to using in the main packages.
If you using nuz for your project, PRs are welcome! 🎉
Update soon! ✍️
Please see our CONTRIBUTING.md 📝
Hieu Lam (@lamhieu-vk).
FAQs
Nuz is a fancy library to implements Micro Frontends compatible with ReactJS and may support more in the future
We found that nuz demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.