
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@airig/cli
Advanced tools
Distribute and manage AI setups across coding agents from one project-local .ai/ directory.
Install the CLI globally to use the short airig command:
npm install --global airig
airig add <owner/repo>[@version]
airig add .
airig update <owner/repo>@<version>
airig remove [owner/repo|.]
airig publish [tag]
For one-off usage without a global install, run the npm package directly:
npx airig add <owner/repo>[@version]
npx airig add .
npx airig update <owner/repo>@<version>
npx airig remove [owner/repo|.]
npx airig publish [tag]
The package is named airig; the installed binary is airig.
airig installs selected AI setup artifacts from immutable GitHub releases into .ai/, then links them into provider-specific config paths. It supports local author dogfooding with add ., explicit version updates, interactive removal, and publishing .ai/ as an ai.zip release asset.
Remote setup releases are pinned to exact versions in .ai/ai.json. add and update verify GitHub release immutability before writing remote content.
.ai/.airig add . to wire local artifacts into your repo.airig publish to upload ai.zip to an immutable GitHub release.airig add yourname/repo.24.11.0 or newer in the Node 24 release line.GITHUB_TOKEN with repository write access when running publish.FAQs
Distribute and manage AI setups across providers
The npm package @airig/cli receives a total of 6 weekly downloads. As such, @airig/cli popularity was classified as not popular.
We found that @airig/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.