
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@async/hygiene
Advanced tools
@async/hygiene hides repository hygiene tooling behind one package, one config file, one CLI command, and one pipeline task.
Consuming repositories should expose a single hygiene gate. The underlying tools are implementation details of this package.
pnpm add -D @async/hygiene
The package is ESM TypeScript, requires Node >=24, and ships the async-hygiene binary.
Create hygiene.config.ts:
import { defineConfig } from "@async/hygiene";
export default defineConfig({
mode: "auto",
targets: {
packages: [{ path: "packages/pipeline" }]
}
});
Modes:
app: repo-level hygiene only.package: repo-level hygiene plus package publish/type/metadata checks.mixed: repo-level hygiene once, package checks for explicit package targets.auto: explicit targets select mixed mode; otherwise a publishable root package selects package mode; private roots fall back to app mode.async-hygiene list
async-hygiene check
async-hygiene check --mode app
async-hygiene check --mode package
async-hygiene check --mode mixed
check prints one combined report and exits non-zero when any hygiene gate fails.
Expose one task:
import { hygieneTask } from "@async/hygiene/pipeline";
import hygieneConfig from "./hygiene.config.ts";
export default definePipeline({
// ...
tasks: {
hygiene: hygieneTask(hygieneConfig),
pack: task({
dependsOn: ["test", "hygiene"],
run: sh`npm --cache .async/npm-cache pack --dry-run`
})
}
});
Do not expose tool-specific task ids in the consuming repo.
FAQs
Hidden hygiene gates for Async apps, packages, and mixed monorepos.
We found that @async/hygiene demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.