
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
@ariestools/aries-dapp-serve
Advanced tools
Aries dapp REST server: serves a dapp backend's S3 layout from one origin with /state, /data, /index subfolders
Dev only. This package is a local development fixture — it accepts any S3 credentials, carries no auth or metrics. It is not meant for production; production dapp backends publish to real object storage (S3/R2).
Serves a dapp backend's layout from a single origin using subfolders
(/state, /data, /index) — the S3-compatible storage half of the
aries dapp local backend. The subfolders are S3 buckets on an embedded
S3-compatible server (s3rver), so any
S3 client writes into them unchanged while readers (browser dapps, curl)
fetch the same layout paths over plain HTTP or optional TLS.
The three buckets:
data — immutable, append-only facts (the source of truth).state — mutable current derived view, rebuilt on an interval by the
DappActor.index — query-optimized derived views, rebuilt on an interval by the
DappActor.This package is the storage layer only. The DappActor that derives state
and index from data, and the composed daemon that runs both the server
and the actor, live in
@ariestools/aries-dapp-core. aries dapp up spawns that
composed daemon.
| Kind | Behavior |
|---|---|
memory | Ephemeral temp directory, wiped on close() / process shutdown |
disk | Caller-owned directory (e.g. ~/.aries/dapp/data); survives restarts; cleanup() is a no-op |
import {
createDiskBacking, createMemoryBacking, startDappServer,
} from '@ariestools/aries-dapp-serve'
const server = await startDappServer({
backing: createDiskBacking('/var/lib/aries-dapp'),
port: 8801,
})
s3 (proxy a remote bucket without embedding s3rver) is not implemented yet.
FAQs
Aries dapp REST server: serves a dapp backend's S3 layout from one origin with /state, /data, /index subfolders
We found that @ariestools/aries-dapp-serve demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.