
Research
6 Malicious Packagist Themes Ship Trojanized jQuery and FUNNULL Redirect Payloads
Six malicious Packagist packages posing as OphimCMS themes contain trojanized jQuery that exfiltrates URLs, injects ads, and loads FUNNULL-linked redirects.
@sentry/warden
Advanced tools
Event-driven agent that reacts to GitHub events and executes skills via Claude Code SDK
Your code is under new management. Agents that review your code - locally or on every PR - using the Skills you already know and love.
Skills, not prompts. Define analysis once, run it anywhere. Bootstrap your environment with skills from conventional directories (.agents/skills/ or .claude/skills/).
Two ways to run. CLI catches issues before you push. GitHub Action reviews every PR automatically.
GitHub-native. Findings appear as inline PR comments with suggested fixes.
# Initialize warden in your repository
npx warden init
# Run on uncommitted changes
# Uses Claude Code subscription if logged in, or set WARDEN_ANTHROPIC_API_KEY
npx warden
# Fix issues automatically
npx warden --fix
git clone git@github.com:getsentry/warden.git
cd warden
pnpm install && pnpm build
pnpm test # unit tests
pnpm test:evals # end-to-end evals (requires API key)
See evals/README.md for the eval framework.
FSL-1.1-ALv2
FAQs
Event-driven agent that reacts to GitHub events and executes skills via Claude Code SDK
The npm package @sentry/warden receives a total of 355 weekly downloads. As such, @sentry/warden popularity was classified as not popular.
We found that @sentry/warden demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Six malicious Packagist packages posing as OphimCMS themes contain trojanized jQuery that exfiltrates URLs, injects ads, and loads FUNNULL-linked redirects.

Security News
The GCVE initiative operated by CIRCL has officially opened its publishing ecosystem, letting organizations issue and share vulnerability identifiers without routing through a central authority.

Security News
The project is retiring its odd/even release model in favor of a simpler annual cadence where every major version becomes LTS.