
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
@axa-ch/alt-pod-test
Advanced tools
This is a Micro Frontend deployable on the AXA.ch WebHub.
To install the pod locally: npm install @axa-ch/alt-pod-test
npm start start local DEV environmentnpm run build to trigger a ESM build needed for Midgardnpm run test to run local testsnpm run release to execute a release to npm (VERY IMPORTANT: Read How To Release on this document).npm run alt-release to execute an alternative pod release to npm (VERY IMPORTANT: Read How To Release an alternative pod in this document).update package.json in the "version": "x.x.x" field. Please follow semver best practices
run npm run release
commit to develop, add git tag containg the same version as in step 1 and push
Execute jenkins jobs (build & deploy) with the version added in point 1
It's possible (but optional) to create an alternative pod besides your actual pod. This alternative pod can be used for some assessments or testing session. An alternative pod can only be deployed to DEV and ACC. There is an extra script for alternative pod releases: alt-release If you execute this script it will change your pod name to alt-pod-your-pod-name, publish a version to npm and after publishing it will change the pod name back to the previous. The pod version will not change unless you change it manually.
For releasing an alternative pod follow these steps:
update package.json in the "version": "x.x.x" field (if you want). Please follow semver best practices
run npm run alt-release
Execute jenkins jobs (build & deploy) with the version added in point 1
While you create your pod you will be asked if it's OK to publish a first vesion of your pod to npm.
If you choose "n" you have to execute the following script (only for your first pod version): npm run first-ever-release
For a first release of an alternative pod you have to execute the following script (only for your first pod version): npm run first-ever-alt-release
FAQs
Micro-Frontend for https://axa.ch/
We found that @axa-ch/alt-pod-test demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 48 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.