
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@buoy-design/cli
Advanced tools
Catch design drift before it ships. Buoy scans your codebase to find where AI-generated code diverges from your design system.
npx ahoybuoy show all
This scans your project without requiring configuration.
#3b82f6 instead of design tokenspadding: 17px instead of spacing variables| Command | Purpose |
|---|---|
buoy show all | Scan for components, tokens, and drift |
buoy drift check | Pre-commit drift validation |
buoy drift fix | Preview or apply drift fixes |
buoy rescue | Measure, repair, guard, and prove improvement |
buoy dock | Configure project (agents, hooks, etc.) |
buoy ahoy | Cloud features (login, GitHub bot, billing) |
The buoy drift fix command suggests and applies fixes for design drift:
buoy drift fix # Preview fixable issues
buoy drift fix --dry-run # Show detailed diffs
buoy drift fix --apply # Apply high-confidence fixes
buoy drift fix --confidence=high # Require high-confidence matches
For an existing codebase, Rescue turns the commands into one reviewable journey:
buoy rescue plan
# Review .buoy/rescue/runs/<run-id>/report.html
buoy rescue apply --run <run-id> --approve
buoy rescue guard --run <run-id> --reason "Reviewed legacy baseline"
buoy rescue report --run <run-id>
Apply requires a clean Git worktree and creates a new buoy/<run-id> branch.
Buoy never commits, pushes, merges, or uploads source code. Ambiguous changes stay
review-required, and buoy rescue rollback restores local backups.
| Level | Score | Description |
|---|---|---|
| exact | 100% | Value exactly matches a design token |
| high | 95-99% | Very close match, safe to auto-apply |
| medium | 70-94% | Close match, review recommended |
| low | <70% | Ambiguous, manual review required |
Buoy works great with AI coding tools:
# Set up AI agents with design system context
buoy dock agents
# Generate CLAUDE.md context
buoy dock context
Buoy auto-detects your framework (React, Vue, Svelte, Angular, Astro) and scans standard paths. No configuration required to get started.
Off by default. After your first drift result in an interactive terminal, Buoy asks once whether it may send anonymous usage pings. Say no and it never asks again.
If you opt in, it sends event names (cli_first_run, cli_drift_found, cli_check_clean, cli_hint_shown, cli_login_started) with counts, the CLI version, and your OS. Never file paths, repository names, code, or account details. A random id in ~/.buoy/config.json groups pings from one install and is not tied to you.
buoy ahoy telemetry # show the setting and the exact payload
buoy ahoy telemetry off # or on
BUOY_TELEMETRY=0, DO_NOT_TRACK=1, or CI in the environment disables it regardless of the setting. JSON and quiet output never send.
FAQs
Catch design drift before it ships
The npm package @buoy-design/cli receives a total of 245 weekly downloads. As such, @buoy-design/cli popularity was classified as not popular.
We found that @buoy-design/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.