Menu

#Packages

88 posts

Feed·
20 of 88 posts
GitHub - glojurelang/glojure: Clojure interpreter hosted on Go, with extensible interop support.
🖼️
234

GitHub - glojurelang/glojure: Clojure interpreter hosted on Go, with extensible interop support.

Hacker News·4 months ago
#XPqszNYO

Clojure interpreter hosted on Go, with extensible interop support. - glojurelang/glojure

15s
Read More
Why Gentoo Linux Endures: Independence, Control and a Volunteer Passion That Outlasts Trends
🖼️
0

Why Gentoo Linux Endures: Independence, Control and a Volunteer Passion That Outlasts Trends

Michał Górny challenges the stereotype that Gentoo Linux exists only for performance chasing through compilation. The distribution delivers independence from corporate control, strong security practices, surprising stability in a rolling model, and…

15s
Read More
I scanned 200 popular MCP server packages. Here is what I found.
🖼️
0

I scanned 200 popular MCP server packages. Here is what I found.

DEV Community: security·weiseer·4 months ago
#38VO6HJu

Open-source supply-chain trust gate for MCP servers, validated on 200 packages. 3 BLOCK findings including 1 hardcoded LLM API key. 6 'official' servers abandoned. Free public API.

15s
Read More
Malicious npm Package ua-parser-js2 Steals SSH Keys and Credentials via Typosquatting
🖼️
0

Malicious npm Package ua-parser-js2 Steals SSH Keys and Credentials via Typosquatting

A malicious npm package called ua-parser-js2 impersonated the legitimate ua-parser-js library to steal sensitive files, environment variables, SSH keys, and credentials from developer machines via a post-install script.…

15s
Read More
PHP's Supply Chain Under Siege: How Packagist Fights Back Against Account Takeovers and Stealthy Malware
🖼️
0

PHP's Supply Chain Under Siege: How Packagist Fights Back Against Account Takeovers and Stealthy Malware

Recent attacks compromised laravel-lang packages and eight others via stolen GitHub credentials and hidden malware in package.json. Packagist's transparency log, Aikido detection, and upcoming immutable versions in Composer 2.10 mark concrete progress…

15s
Read More
I built an open-source dependency intelligence platform in TypeScript — here's how it works
🖼️
0

I built an open-source dependency intelligence platform in TypeScript — here's how it works

DEV Community: security·Zayd Mulani·4 months ago
#vJGSpopG
#dev#depgraph#packages#risk#pnpm#maintainer

Most teams find out their dependencies are risky after something breaks. A maintainer disappears, a...

15s
Read More
Introducing skills, the open agent skills ecosystem - Vercel
📰
0

Introducing skills, the open agent skills ecosystem - Vercel

Vercel News·Andrew Qu·4 months ago
#omoONU0B
#vercel#skills#skill#packages#install#package

Introducing skills, a CLI for installing and managing agent “skill packages.” Add a skill package with npx skills add , with more commands planned.

15s
Read More