
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@buildinternet/releases-core
Advanced tools
Pure helpers shared by the Releases registry — schema, categories, slicing, IDs, slugs, tokens.
Scope: pure, runtime-neutral helpers shared by this monorepo and the OSS CLI — schema, categories, dates, slicing, IDs/slugs, tokens, CLI contracts. Nothing DB-coupled beyond schema definitions and nothing worker-only lives here — that goes in core-internal.
Pure helpers shared by the Releases registry and the Releases CLI — schema, categories, slicing, IDs, slugs, tokens, CLI contracts.
Imported as @buildinternet/releases-core/<subpath>.
| Subpath | Purpose |
|---|---|
schema | Drizzle ORM table definitions (source of truth for the Releases D1 database). |
categories | Canonical category list, validation, and alias resolution (resolveCategorySlug, parseCategoryAliases). |
dates | Date cutoffs and helpers. |
changelog-range | Pure range parsing. |
changelog-slice | Token-aware CHANGELOG slicing. |
changelog-publish | Plan a changelog push into the upsert-content batch body (single-file ## sections and directory frontmatter). Shared by the publish Action and releases publish. |
overview | Overview staleness + preview helpers. |
id | Prefixed nanoid generators and entity-type lookup. |
slug | Slug generation. |
tokens | Token counting (tiktoken-backed). |
cli-contracts | Shared --json envelope types for the CLI. |
d1-limits | Backend capability constants (D1_MAX_BINDINGS, IN_ARRAY_CHUNK_SIZE) for single-column IN chunking. |
Published from the buildinternet/releases monorepo. The upstream packages/core/ directory is the single source of truth; both the monorepo and the OSS CLI consume this package from npm.
Changelog-publish fixtures (single-file markdown and directory MDX) ship in fixtures/changelog-publish/ for the CLI to reuse.
DB-coupled and worker-only helpers (release upsert, hashing, webhook signing) live in the monorepo under @releases/core-internal and are not published.
FAQs
Pure helpers shared by Releases Index — schema, categories, slicing, IDs, slugs, tokens.
The npm package @buildinternet/releases-core receives a total of 308 weekly downloads. As such, @buildinternet/releases-core popularity was classified as not popular.
We found that @buildinternet/releases-core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.