
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@codai/axiom-apply
Advanced tools
Transactional two-phase-commit apply engine for AXIOM v2 manifest bundles: containment, staging, journal, scoped rollback
Transactional apply engine for AXIOM v2 ManifestBundles (design §4). apply() never throws; every
failure is an AxiomError code from @codai/axiom-schema surfaced in ApplyResult.error.
root is ever written. Every artifact path is schema-validated (POSIX-relative, NFC,
Windows reserved names rejected on every OS), checked for case-insensitive collisions, walked segment by
segment with lstat (symlink/junction → ERR_SYMLINK_IN_PATH) and realpath-contained (ERR_CONTAINMENT).ERR_DIGEST_MISMATCH,
ERR_SIZE_MISMATCH) and again after every write; the whole bundle is resolved before the first write..axiom/staging/<digest>/ (tmp → fsync →
rename). Phase 2 re-verifies each target's pre-image right before its rename (ERR_PREIMAGE_CHANGED,
closes the check-then-apply TOCTOU window), backs up pre-images, then renames. Any phase-2 error rolls
back in reverse order, scoped to exactly the manifest's paths, and returns status: "rolled-back"..axiom/lock (O_EXCL, {pid, hostname, startedAt, manifestDigest}); stale
if the pid is dead or older than 1 h; 30 s wait → ERR_LOCKED.status: "noop".committing/rolling-back is rolled back at the next apply; rollback(root, digest) is exposed for the CLI.mode: "dry-run" runs phase 1 only, returns a unified diff (≤ 1 MiB) and leaves the tree untouched.mode: "pr" wraps the fs apply in a git branch + commit (git.ts, spawn args array, no shell):
branch validated by regex + git check-ref-format --branch, default name axiom/<name>/<digest12>
(deterministic), touched paths must be clean (git status --porcelain -- <paths>), git switch -c,
fs apply, git add -- <paths> explicit only, git commit --quiet -F - with the message on stdin,
result.git = { branch, commit, compareUrl? }. Hooks are honoured. No push, no PR creation, no
network — run gh pr create --head <branch> afterwards. Failures: ERR_GIT_NOT_REPO, ERR_GIT_DIRTY,
ERR_GIT_BRANCH_EXISTS, ERR_GIT_BRANCH_INVALID, ERR_GIT_NOT_FOUND, ERR_GIT_FAILED; an fs or commit
failure rolls the apply back and drops the branch..axiom/lock; the pre-image check narrows the
window to the instant before rename but cannot close it on POSIX/NTFS without a snapshotting FS.fsync is skipped on Windows; file mode 0755 is recorded but not applied on Windows.ref artifact sources are not fetched in v2.0 (ERR_REF_OFFLINE); only inline blobs and the local CAS.keepBackups, default 3 manifests) are a convenience, not a version-control system..axiom/ layout.axiom/lock single-writer lockfile
.axiom/staging/<hex>/ full new tree, deleted after commit or on any failure
.axiom/journal/<hex>.json Journal (phase + steps), fsynced before phase 2
.axiom/backup/<hex>/ pre-images of overwritten/deleted files (hardlink, else copy)
.axiom/applied/<hex>.json ApplyResult; presence == idempotency marker
.axiom/cas/sha256/<aa>/<hex> optional content-addressed store read by resolveContent
.axiom/tmp/ case-sensitivity probe scratch
Note: this package keeps isolatedDeclarations: true from the base tsconfig.
FAQs
Transactional two-phase-commit apply engine for AXIOM v2 manifest bundles: containment, staging, journal, scoped rollback
The npm package @codai/axiom-apply receives a total of 615 weekly downloads. As such, @codai/axiom-apply popularity was classified as not popular.
We found that @codai/axiom-apply demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.