
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@create-cmp/harness
Advanced tools
The create-cmp verify lane — the machine-owned harness code every stamped app carries byte-identical: evidence receipts, spec coverage, approvals, conformance reporting, golden trees, a11y, and the preview/inspector libs. Dependency-free ESM, vendored int
The verify lane every create-cmp app carries — the machine-owned half of a stamped project, published as the single source of truth it is vendored from.
A create-cmp project contains app-owned files (screens, specs, golden baselines, approvals, e2e flows — the app) and machine-owned files (the lane — engine code, byte-identical in every app ever stamped, carrying no app content). The boundary is mechanical, with no list to maintain:
machine-owned == the .mjs files directly under qa/ and qa/lib/
src/lib/harness-region.mjs is that rule as code. Three properties hang off it:
create-cmp.json.qa/verify.mjs
to force every step green and the receipt still validates, because the
edited checker is just part of the hashed surface.create-cmp upgrade --harness swaps the whole
region. Three-way-merging a derived artifact was the prior failure: engine
code produced conflict noise in every app while containing nothing
app-specific to preserve.Generated projects never npm install this. The scaffold drops a
byte-identical copy of src/ into the project's qa/, so
node qa/verify.mjs runs offline, in CI, and air-gapped, with no install
step and no registry reachable. This package exists so that copy has a
published, citable source of truth — and so the region's integrity mechanism
is installable on its own (below). In the create-cmp repo,
node scripts/sync-harness.mjs re-vendors and parity tests pin
byte-equality across package ↔ template ↔ fresh scaffold.
npm install @create-cmp/harness
The part worth consuming standalone is the machine-owned-region integrity
check — the same check qa/verify.mjs runs as its first step in every
profile, as plain functions over a directory tree:
import { isHarnessFile } from "@create-cmp/harness/harness-region";
import {
writeHarnessLock,
checkHarnessIntegrity,
describeIntegrity,
} from "@create-cmp/harness/lib/harness-lock.mjs";
isHarnessFile("qa/verify.mjs"); // true — machine-owned
isHarnessFile("qa/approvals.json"); // false — app state, never part of the region
writeHarnessLock(projectRoot, { version: "1.0.0" });
describeIntegrity(checkHarnessIntegrity(projectRoot));
// "@create-cmp/harness 1.0.0 — 2 files verified"
// …edit a lane file in place, then check again:
// "@create-cmp/harness 1.0.0 — 1 modified"
checkHarnessIntegrity returns { status: "intact" | "modified" | "unlocked", name, version, modified, missing, extra, fileCount } — naming exactly which
files drifted, so an upgrade knows what it is replacing. hashHarnessRegion(root)
gives { sha256, fileCount, files } (a per-file digest map) with no lock to
compare against. A corrupt or truncated lock reads as unlocked, never as
intact.
src/verify.mjs is the lane's CLI entry (what a vendored copy runs as
qa/verify.mjs), composed from the src/lib/*.mjs modules: spec-coverage
scanning, the approvals gate, golden-tree / a11y / conformance wiring, the
device lease, the step cache, the flight recorder, the evidence-receipt
writer. Each is individually importable (@create-cmp/harness/lib/<name>.mjs,
extension optional), but they are written to run inside a scaffolded
Compose Multiplatform project — they expect composeApp/, specs/, and
gradlew on disk. They are not a general-purpose toolkit.
Two modules are the exception by design: lib/inputs-hash.mjs and
lib/receipt-validate.mjs are byte-identical vendored copies of
@create-cmp/receipts
(parity-tested), kept so this package needs no npm dependency either. If you
only want receipt validation, depend on @create-cmp/receipts directly.
node_modules will not verify the project that installed it. It works
vendored into a project's qa/, which create-cmp does at scaffold and
upgrade time.@create-cmp/harness@X?" needs a
comparison against the published package's own digests, which is the
upgrade flow's job, not the lock's.qa/evidence/latest.json
on disk; committing or hosting them is the project's choice.This package versions independently of create-cmp-cli. The lane changes
far more often than the template's app shape; coupling the two forced an
app-shape release for every lane fix. A generated project records both — the
engine version that stamped its shape and the harness version that issues its
verdicts — and can upgrade either without the other.
FAQs
The create-cmp verify lane — the machine-owned harness code every stamped app carries byte-identical: evidence receipts, spec coverage, approvals, conformance reporting, golden trees, a11y, and the preview/inspector libs. Dependency-free ESM, vendored int
The npm package @create-cmp/harness receives a total of 2 weekly downloads. As such, @create-cmp/harness popularity was classified as not popular.
We found that @create-cmp/harness demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.