
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
@argosvix/cli
Advanced tools
Argosvix CLI — one-command onboarding for AI agent observability. `npx @argosvix/cli init` authenticates in the browser, installs the SDK, wires the MCP server, and sends a test event.
One-command onboarding for Argosvix — AI agent observability.
npx @argosvix/cli init
init does the whole setup for you:
@argosvix/sdk for Node, argosvix for Python).ARGOSVIX_API_KEY to .env (and adds .env to .gitignore).wrap() snippet to add to your code (or let your AI apply it).The browser-issued key is least-privilege (read + write:records = read + ingest only). It cannot change alerts or settings; create a full key from the dashboard if you need one.
npx @argosvix/cli init # full setup (browser approve once)
npx @argosvix/cli init --force-login # re-authenticate even if a key exists
npx @argosvix/cli login # just (re)authenticate and write .env
npx @argosvix/cli doctor # diagnose: key / API reachability / MCP / runtime
init starts a temporary loopback server on 127.0.0.1, opens
https://dashboard.argosvix.com/<locale>/cli/authorize with a PKCE code_challenge
state, and waits for the browser redirect. You approve in the dashboard; the
backend returns a one-time code to the loopback; the CLI exchanges it (with the PKCE
verifier) for the API key. The key is never pasted by hand and never leaves your machine
beyond the .env you control.ARGOSVIX_API_BASE (default https://ingest.argosvix.com)ARGOSVIX_DASHBOARD_BASE (default https://dashboard.argosvix.com)ARGOSVIX_LOCALE (default en)Node.js >= 20.
FAQs
Argosvix CLI — one-command onboarding for AI agent observability. `npx @argosvix/cli init` authenticates in the browser, installs the SDK, wires the MCP server, and sends a test event.
The npm package @argosvix/cli receives a total of 31 weekly downloads. As such, @argosvix/cli popularity was classified as not popular.
We found that @argosvix/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.