
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
@claudexor/interview
Advanced tools
Spec interview: a hierarchical clarify-quiz that turns a vague task into a frozen, versioned, diffable SpecPack which maps deterministically into a TaskContract.
Internal package of Claudexor — Spec interview: a hierarchical clarify-quiz that turns a vague task into a frozen, versioned, diffable SpecPack which maps deterministically into a TaskContract.
Published as part of the Claudexor toolchain; it follows the monorepo's
lockstep version and has no separate semver contract. Use the claudexor
CLI (or @claudexor/cli) as the supported entry point.
FAQs
Spec interview: a hierarchical clarify-quiz that turns a vague task into a frozen, versioned, diffable SpecPack which maps deterministically into a TaskContract.
We found that @claudexor/interview demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.