
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@buildinternet/uploads
Advanced tools
CLI and client for uploads.sh — workspace-scoped image hosting for GitHub embeds
CLI and client for uploads.sh — upload files, get public URLs, and produce GitHub-ready markdown. Successor to the R2 scripts in buildinternet-skills/github-screenshots.
Binary: uploads (also pnpm uploads from repo root after pnpm install).
Install globally or run a pinned version without installing:
npm install --global @buildinternet/uploads
npx @buildinternet/uploads@0.1.0 --help
pnpm uploads setup --env-file .env
pnpm uploads attach ./before.png ./after.png --env-file .env
pnpm uploads put ./shot.png --env-file .env
pnpm uploads put ./after.png --pr 123 --comment --env-file .env
pnpm uploads doctor --env-file .env
Commands: attach, put, comment, list, delete, setup, config, doctor, health.
attach is the agent-friendly default for GitHub media. It accepts one or more files,
infers the pull request for the current branch via gh, uploads stable URLs, and creates
or updates one managed attachments comment. Use --pr, --issue, and --repo to select
the target explicitly, or --no-comment to upload without changing GitHub comments.
Config layers (first match wins): CLI flags → env vars → --env-file → ~/.config/buildinternet/config. See config.example for keys.
import { createUploadsClient } from "@buildinternet/uploads";
Agent/MCP helpers: @buildinternet/uploads/agent (createUploadsWorkerFileTools for Workers).
src/
cli.ts Entry + help
commands.ts put, list, delete, comment, …
client.ts HTTP client for the API
github.ts PR/issue key paths + attachment comments
embed.ts Markdown image output
bin/uploads.js Bin shim
pnpm build # tsc → dist/
pnpm typecheck
pnpm test
pnpm pack:check # verify the npm tarball contents
Maintainer release instructions: docs/releasing.md.
Agent-oriented usage: skills/uploads-cli/SKILL.md. REST details: docs/api.md.
FAQs
CLI and client for uploads.sh — workspace-scoped image hosting for GitHub embeds
The npm package @buildinternet/uploads receives a total of 612 weekly downloads. As such, @buildinternet/uploads popularity was classified as not popular.
We found that @buildinternet/uploads demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.