
Security News
GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.
@ariestools/aries-datalake-core
Advanced tools
Shared types and contracts for Aries on-demand XL1 datalake provisioning
@ariestools/aries-datalake-coreShared Aries datalake wire contracts, path builders, payload types, scope constants, and Node token codecs.
@ariestools/aries-datalake-core is the Node entry point. It includes the browser-safe contracts plus HS256 challenge, session, and datalake token signing and verification.@ariestools/aries-datalake-core/browser is the browser entry point. It contains wire types, route builders, error types, and the canonical control/data audience and scope constants. It does not import Node cryptography, filesystem APIs, environment variables, or credential storage.Use the /browser entry point in browser applications. JWT verification belongs on the Aries control and data planes; importing the wire contracts does not make browser code an authorization boundary.
Browser wallet JWTs are short-lived, audience-bound bearer credentials. The server additionally enforces the exact HTTP Origin, signed origin, canonical scope vocabulary, signer identity, and current datalake ACL. A signed statement does not by itself establish truth, consent, privacy, or permanence.
FAQs
Shared types and contracts for Aries on-demand XL1 datalake provisioning
We found that @ariestools/aries-datalake-core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.

Research
/Security News
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.