
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
ux-buildkit
Advanced tools
The buildkit is platform idependant, we should be able to include it on all our Drupal and WordPress projects.
All tests are run on the precommit hook but can be overidden using a --noverify flag (not yet)
under the hood for scss testing we use stylelint, styles are broken up into 3 major categories:
Linting tests can be run using NPM Scripts. If you are not fimialr with this concept please take time to review it. NPM Scripts allows us to have one set of wrapper scripts that we can interchangeably use should we ever decide to move to another tool.
See the main gulpfile.js for a full list of tests that can be run.
The two main factors behind linting our files are 1, for consistency 2, for readability. We use the recommened guidelines from sass-guidelines as well as a few others to maintain this philosophy.
Another benefit is automation, we should not spending time repeating tasks that can be automated, such as code reviews. Code reviews can offer vailble feedback best on the vest practices and the viability of our code but reviewers should not have to worry about the granular details of things like indentation - this is what linters are for!
https://www.npmjs.com/package/pre-commit https://www.npmjs.com/package/pre-push https://www.npmjs.com/package/copy
FAQs
Front-end build tools for custom Drupal theme.
We found that ux-buildkit demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.