
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
packs-components
Advanced tools
These are a set of standard components for importing into a packs survey project. See individual component folders for specific documentation.
These are a set of standard components for importing into a packs survey project. See individual component folders for specific documentation.
=======
Incrementing version by 1 to republish
work with baseline-demographics-2
work with baseline3
work with baselineUK
work with baseline2
remove timeout
Add prolific message at the end
change placeholder for new baseline
fix bug
Add snapshot as survey name.
block bigger than 30 dispaly error message
fix trials last block bug
remove randomization component debugger
add numberof trio for tradeoff randomization according to another parameter : number of trio
make the robot go to next block authomaticly / add hiden input
add some component for the quality cotrol flow chart
get rid of hit next hit button and make the robot know we are in the last page
blockNumber as number.
Randomize: the current state appear with 100% probability at the first block.
Add an empty span in the bottom of TurkSubmit page.
Add pathName to the next hit url.
Next hit in TurkSubmit component.
Adding id to to loading and warning messages. Add an empty span in the bottom of the page (Form and Markdown).
Robbie's last version
FAQs
These are a set of standard components for importing into a packs survey project. See individual component folders for specific documentation.
We found that packs-components demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.