
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@ronin-dist/render
Advanced tools
> [!IMPORTANT] > Due to a limitation in Bun, RENDER currently cannot be linked. You will have to edit its source files inside the `node_modules` directory of the app you are running it for. This will be fixed as soon as possible.
[!IMPORTANT]
Due to a limitation in Bun, RENDER currently cannot be linked. You will have to edit its source files inside thenode_modulesdirectory of the app you are running it for. This will be fixed as soon as possible.
First, link it to Bun's global dependency cache:
bun link
Then link it inside the app where you would like to use it:
bun link @ronin-dist/render
And finally, run it from the package.json of the app:
render
You can run the test suite with the following command:
bun test
To publish a new release of RENDER using GitHub Actions, you only need to press "Run workflow" on this page and pick the desired kind of release.
Afterward, please make sure to add it to the list of GitHub Releases, as the GitHub Action currently only updates package.json, creates a Git tag, and releases the update to npm. It does not create a GitHub Release.
FAQs
> [!IMPORTANT] > Due to a limitation in Bun, RENDER currently cannot be linked. You will have to edit its source files inside the `node_modules` directory of the app you are running it for. This will be fixed as soon as possible.
We found that @ronin-dist/render demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.