
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
@blacklake-systems/depth-sdk
Advanced tools
BlackLake Depth — durable workflow runtime for AI agent workflows. Runs under Surface governance.
⚠️ Deprecated. This package is now part of the unified
blacklakenpm package. Installblacklakeandimport { workflow, step } from 'blacklake'. See the migration doc for sed-style search-and-replace examples. This package will continue to ship as a thin re-export through the next two minor versions.
Durable workflows for BlackLake — long-running AI work as TypeScript async functions, persisting each step to a local SQLite database so runs can resume from where they left off after a crash or restart. Now part of the unified blacklake package.
BlackLake is AI control infrastructure and analytics. Surface evaluates tool calls against your policies and budgets before they execute, routes approvals, records cost, and signs receipts. Run Surface at console.blacklake.systems or locally via npx blacklake serve; run Depth workflows from the npm package and connect them to whichever Surface control plane you use.
npm install @blacklake-systems/depth-sdk
Sign up at console.blacklake.systems for hosted Surface when you need shared controls, then write a workflow:
import { workflow, step } from '@blacklake-systems/depth-sdk';
export default workflow('expense-report', async (ctx) => {
const summary = await step(ctx, 'summarise', async () => {
return await ctx.llm('anthropic:claude-sonnet-4-6', {
prompt: 'Summarise this month\'s expenses.',
});
});
await step(ctx, 'file-report', async () => {
// tool calls route through Surface for governance automatically
await ctx.tool('filesystem.writeFile', {
path: './report.md',
content: summary,
});
});
return { summary };
});
Run it with the CLI:
npx @blacklake-systems/depth-cli run workflow.ts
Or connect the workflow to hosted Surface at console.blacklake.systems.
If you prefer to run Surface locally, start it first:
npx @blacklake-systems/surface-cli
Depth detects Surface at localhost:3100 automatically — no additional configuration needed.
When Surface is reachable, Depth automatically:
When Surface is not reachable, tool calls execute directly.
workflow(name, fn)Define a durable workflow.
import { workflow } from '@blacklake-systems/depth-sdk';
export default workflow('my-workflow', async (ctx, input: { topic: string }) => {
// ctx.llm, ctx.tool, and step() are available here
return { result: 'done' };
});
step(ctx, name, fn)Wrap a unit of work in a durable step. The return value is persisted; on replay the function is skipped and the stored value is returned.
import { step } from '@blacklake-systems/depth-sdk';
const result = await step(ctx, 'step-name', async () => {
return await someExpensiveOperation();
});
ctx.llm(model, options)Call a language model. Supported prefixes: anthropic:, openai:, ollama:.
const text = await ctx.llm('anthropic:claude-sonnet-4-6', {
prompt: 'Write a haiku about durable execution.',
});
ctx.tool(name, args)Invoke a tool. When Surface is running, the call is governed before execution.
await ctx.tool('filesystem.writeFile', { path: './out.md', content: text });
Full documentation at blacklake.systems/docs.
FAQs
BlackLake Depth — durable workflow runtime for AI agent workflows. Runs under Surface governance.
The npm package @blacklake-systems/depth-sdk receives a total of 7 weekly downloads. As such, @blacklake-systems/depth-sdk popularity was classified as not popular.
We found that @blacklake-systems/depth-sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.