
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@codemirror/state
Advanced tools
[ WEBSITE | DOCS | ISSUES | FORUM | CHANGELOG ]
This package implements the editor state data structures for the CodeMirror code editor.
The project page has more information, a number of examples and the documentation.
This code is released under an MIT license.
We aim to be an inclusive, welcoming community. To make that explicit, we have a code of conduct that applies to communication around the project.
The Monaco Editor is the code editor that powers VS Code, offering rich IntelliSense, validation, and advanced editing features. Compared to @codemirror/state, Monaco is a more comprehensive solution that includes its own state management but is heavier and less modular.
Ace is another embeddable code editor offering a wide range of features and language support. While it also manages editor state and provides similar functionality, it is designed as a monolithic package, making it less flexible than the modular approach of CodeMirror.
Draft.js is a framework for building rich text editors in React, focusing on immutable content and state management. It differs from @codemirror/state by being React-specific and focusing more on rich text editing rather than code editing, but it shares the concept of managing editor state in a comprehensive way.
FAQs
Editor state data structures for the CodeMirror code editor
The npm package @codemirror/state receives a total of 0 weekly downloads. As such, @codemirror/state popularity was classified as not popular.
We found that @codemirror/state demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.