
Security News
Lovable’s OJ Rewrites Vite’s Dev Server in Rust as AI Lowers the Cost of Forking Open Source
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.
@contentrain/types
Advanced tools
@contentrain/typesShared TypeScript types for the Contentrain ecosystem.
Start here:
This package is the common schema layer used by:
@contentrain/mcpcontentrain@contentrain/query@contentrain/rulesIt defines the stable type vocabulary for models, config, metadata, validation, scanning, context files, and provider contracts (enabling third-party RepoProvider implementations).
Use @contentrain/types when you are:
RepoProvider for a new git backendpnpm add @contentrain/types
Core unions:
FieldTypeModelKindContentStatusContentSourceWorkflowModeStackTypePlatformContextSourceCollectionRuntimeFormatLocaleStrategyCore interfaces:
FieldDefModelDefinitionModelSummaryContentrainConfigVocabularyEntryMetaAssetEntryValidationErrorValidationResultScaffoldTemplateScanCandidateDuplicateGroupGraphNodeProjectGraphScanCandidatesResultScanSummaryResultContextJsonStorage/runtime helper types:
SingletonContentFileCollectionContentFileDictionaryContentFileCollectionEntryCollectionContentOutputDocumentEntryDocumentContentOutputSingletonMetaCollectionMetaDocumentMetaDictionaryMetaNormalize/plan types:
NormalizePlanNormalizePlanModelNormalizePlanExtractionNormalizePlanPatchProvider contracts (re-exported from provider.ts — implement these to add a new git backend):
RepoProviderRepoReaderRepoWriterProviderCapabilitiesFileChangeCommitAuthorCommitApplyPlanInputBranchFileDiffMergeResult (includes optional sync?: SyncResult for local-worktree providers)LOCAL_CAPABILITIES (const — capability set for LocalProvider)Git transaction types:
SyncResultContentrainErrorValidate functions (pure, dependency-free):
validateSlug(slug) — kebab-case slug validationvalidateEntryId(id) — entry ID format validationvalidateLocale(locale, config) — locale format + config support checkdetectSecrets(value) — detect potential secrets in field valuesvalidateFieldValue(value, fieldDef) — full field schema validation (type, required, min/max, pattern, select)Serialize functions (pure, dependency-free):
sortKeys(obj, fieldOrder?) — recursive key sorting for canonical outputcanonicalStringify(data, fieldOrder?) — deterministic JSON serializationgenerateEntryId() — 12-char hex ID generationparseMarkdownFrontmatter(content) — parse YAML frontmatter + body from markdownserializeMarkdownFrontmatter(data, body) — serialize data + body into markdown frontmatterConstants:
CONTENTRAIN_DIR — default .contentrain folder nameCONTENTRAIN_BRANCH — default contentrain branch name for content trackingPATH_PATTERNS — file path conventions for models, content, metaSLUG_PATTERN — regex for valid slugsENTRY_ID_PATTERN — regex for valid entry IDsLOCALE_PATTERN — regex for valid locale codesCANONICAL_JSON — serialization rules (indent, encoding, trailing newline, key sort)SECRET_PATTERNS — regex patterns for secret detectionThis package is intended to be the shared public contract across the Contentrain ecosystem.
In practice that means:
RepoProvider contract enables third-party implementations without depending on @contentrain/mcp internalsimport type {
ContentrainConfig,
FieldDef,
ModelDefinition,
ValidationResult,
} from '@contentrain/types'
const fields: Record<string, FieldDef> = {
title: { type: 'string', required: true },
slug: { type: 'slug', required: true, unique: true },
}
const model: ModelDefinition = {
id: 'blog-post',
name: 'Blog Post',
kind: 'collection',
domain: 'blog',
i18n: true,
fields,
}
const config: ContentrainConfig = {
version: 1,
stack: 'next',
workflow: 'review',
locales: { default: 'en', supported: ['en', 'tr'] },
domains: ['blog'],
}
const result: ValidationResult = {
valid: true,
errors: [],
}
Type-only usage:
import type { ModelDefinition, ContentrainConfig } from '@contentrain/types'
Mixed usage (types + runtime functions):
import type { FieldDef, ValidationError } from '@contentrain/types'
import {
validateFieldValue,
validateSlug,
detectSecrets,
canonicalStringify,
parseMarkdownFrontmatter,
} from '@contentrain/types'
Provider contract usage (for custom RepoProvider implementations):
import type { RepoProvider, ProviderCapabilities } from '@contentrain/types'
export class MyCustomProvider implements RepoProvider {
readonly capabilities: ProviderCapabilities = {
localWorktree: false,
sourceRead: true,
sourceWrite: true,
pushRemote: true,
branchProtection: true,
pullRequestFallback: true,
astScan: false,
}
// ...implement RepoProvider methods
}
Studio (Nuxt 4, web) cannot import @contentrain/mcp directly because MCP depends on Node.js-only packages (simple-git, @modelcontextprotocol/sdk). The validate and serialize functions in this package are pure, dependency-free, and browser-compatible — designed for Studio to share the same validation contract as MCP.
@contentrain/types| Function | Use case |
|---|---|
validateSlug(slug) | Form validation for document slugs |
validateEntryId(id) | Validate collection entry IDs |
validateLocale(locale, config) | Locale picker validation |
detectSecrets(value) | Content editor secret detection warnings |
validateFieldValue(value, fieldDef) | Full field-level validation in content forms |
canonicalStringify(data, fieldOrder?) | Preview canonical JSON output |
parseMarkdownFrontmatter(content) | Document editor frontmatter parsing |
serializeMarkdownFrontmatter(data, body) | Document editor serialization |
generateEntryId() | Client-side entry ID generation |
SECRET_PATTERNS | Extend or customize secret detection |
These require file system I/O or Node.js dependencies:
checkRelation() — validates relation references against actual content files on diskvalidateProject() — full project validation with file readingwriteContent() / deleteContent() — content persistence with git worktreeresolveContentDir() / resolveJsonFilePath() — path resolution with node:pathvalidateFieldValue handles schema-level checks. Two things require external state:
These are left to Studio's server-side or API layer to implement on top of the pure validation.
@contentrain/types exists so every package in the monorepo speaks the same domain language.
Examples:
ModelDefinitionContextJsonModelDefinition and FieldDefRepoProvider to plug into MCPThis package should stay:
From the monorepo root:
pnpm --filter @contentrain/types build
pnpm --filter @contentrain/types test
pnpm --filter @contentrain/types typecheck
@contentrain/mcpcontentrain@contentrain/query@contentrain/rulesMIT
Shared shapes for the WordPress → static-site migration pipeline. They exist here — in the one MIT package every side may depend on — because the documents cross repository and license boundaries: a GPL WordPress plugin produces them, a proprietary migration service consumes them, an open emitter renders from them.
| Contract | Role |
|---|---|
RawIR | Source-faithful extraction of a WordPress site (posts, terms, menus, comments, media, redirects) with provenance: which access rung produced it (rest_public → rest_auth → wxr → bridge). Unresolved references are kept and marked, never dropped. |
CapabilityManifest | Evidence-based inventory of what the site uses (SEO, forms, comments, i18n, ACF, …) — the input for migration planning and the "what happens to X" conversation. |
ProjectIR | The reproducible model of the site: route model, layout families, component variants, query bindings, design tokens. Not "this page's HTML" — the design system that generates unseen pages correctly. |
MigrationHandoff | What the migration hands the user: repository, per-capability dispositions, and offers for runtime capabilities (with cost comparison) — offering is this document's job; fulfilling is the receiving product's. |
All four are plain JSON (snake_case keys), stamped with MIGRATION_CONTRACT_VERSION.
FAQs
Shared TypeScript types for Contentrain ecosystem
The npm package @contentrain/types receives a total of 890 weekly downloads. As such, @contentrain/types popularity was classified as not popular.
We found that @contentrain/types demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.