
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
Command line companion for a self-hosted LFSX Git LFS server.
npm install -g @ferrlabs/lfsx # or: cargo install lfsx
lfsx --url https://lfs.example.com doctor --repo my-org/my-project
lfsx --url https://lfs.example.com gc --repo my-org/my-project --dry-run
doctor checks that the server is up, that its storage is writable, that your token is accepted,
and — the one that matters — that the URL it advertises for transfers is the URL you reached it
on. A mismatch there lets negotiation succeed while every transfer fails.
gc reads the objects the repository still references and asks the server to sweep the rest. It
refuses to run from a shallow clone, which would retain a fraction of what it should.
The server itself is lfsx-server.
FAQs
Unknown package
The cargo package lfsx receives a total of 537 weekly downloads. As such, lfsx popularity was classified as not popular.
We found that lfsx demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.