
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@0disoft/mensor-cli
Advanced tools
Command-line interface for checking Mensor project contracts.
pnpm add --save-dev @0disoft/mensor-cli
Node.js 22 or newer is required.
Run the default DiagnosticReport v1 output:
pnpm exec mensor check . --json
Select Check Output v2 when the consumer needs explicit inspection coverage:
pnpm exec mensor check . --json --report-version 2
Exit status 0 means every configured static contract check passed. It does
not prove runtime application behavior. When a project omits RouteIndex,
application route declarations are not inspected.
Mensor does not execute project source or configuration while checking it.
Mensor is licensed under Apache-2.0.
FAQs
CLI for checking Mensor project contracts.
The npm package @0disoft/mensor-cli receives a total of 13 weekly downloads. As such, @0disoft/mensor-cli popularity was classified as not popular.
We found that @0disoft/mensor-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.