
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@codai/axiom-canon
Advanced tools
RFC 8785 JSON canonicalization, sha256 digests and in-toto Statement/SLSA provenance builders for AXIOM
Zero-dependency canonicalization and attestation primitives for AXIOM v2.
What: RFC 8785 JSON Canonicalization (JCS), sha256 content addressing
(sha256:<hex>), an in-toto Statement v1 / SLSA Provenance v1 builder, and
DSSE Pre-Authentication Encoding. Only node:crypto at runtime.
Why: every AXIOM artefact (Manifest, Plan, facts, Statement) is identified
by the hash of its canonical bytes. Deterministic serialization is what makes
manifestDigest reproducible across OSes and lets verify byte-compare
instead of trusting a parser. Lifted from codai/packages/rules-core.
canonicalize(value): string — JCS; throws CanonicalizeError on NaN,
bigint, lone surrogates. undefined members are dropped.sha256Hex, sha256Digest, digestRef, parseDigestRefcanonicalHash(value), canonicalDigestRef(value), verifyCanonical(text)buildStatement(input): InTotoStatementV1 + constants
IN_TOTO_STATEMENT_V1, SLSA_PROVENANCE_V1, AXIOM_BUILD_TYPE, AXIOM_BUILDER_IDpae(payloadType, payload): Uint8Array, DSSE_IN_TOTO_PAYLOAD_TYPEFAQs
RFC 8785 JSON canonicalization, sha256 digests and in-toto Statement/SLSA provenance builders for AXIOM
The npm package @codai/axiom-canon receives a total of 79 weekly downloads. As such, @codai/axiom-canon popularity was classified as not popular.
We found that @codai/axiom-canon demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.