
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@cymule/sdk
Advanced tools
This package authors cymule.ir/2 Plan Candidates and calls a trusted Cymule
Engine. It does not implement canonical sealing or runtime semantics.
FlowBuilder.definition() adds a reusable definition to the same immutable
Plan and invoke() calls it with explicit input and result binding. Logical
latest-compatible registry resolution is performed by the Rust M4 linker before
sealing, never by the SDK.
npm install cymule
import { CliEngine, FlowBuilder, ResourceBuilder } from "cymule";
Resource Candidates use the same Engine boundary:
const resource = new CliEngine("./target/debug/cymule").sealResource(
ResourceBuilder.text("input for another Run"),
);
Use ResourceBuilder.external for content-addressed/version-pinned objects,
directories, collections, snapshots, and live references. Concrete access stays
behind resolver plugins; Resource Candidates never contain credentials.
WaitActivationBuilder creates provider-neutral signal or timer delivery
records. CliEngine.verifyWaitActivation validates the closed wire contract;
the durable runtime remains responsible for matching pending waits and admitting
the activation through CAS.
VirtualWorkControl is a transport-neutral interface for querying identified
M3 attempt occurrences and submitting owner/work/lease/time-fenced resolution
commands.
VirtualWorkControlBuilder creates success, retry, failure, and cancellation
commands without choosing a scheduler or worker transport.
The same interface accepts adapter-produced region split/merge plans with
opaque cursor preconditions and coverage evidence; SDK code never partitions
cursor strings itself.
It also carries completed-region compaction and exact-occurrence rehydration
commands. VirtualArchive is only an immutable byte seam; the Rust controller
computes and verifies manifest and certificate identity before M1 admission.
VirtualSchedulingControl carries capacity-slot claims, lease renewals,
explicit expired-claim recovery, and future Run-weight updates. Builders require
work and lease fences plus logical Clock values; they never run a worker loop or
infer expiry from JavaScript time.
The package is published from GitHub Actions with npm trusted publishing and provenance. The Rust Engine remains the semantic authority.
FAQs
TypeScript authoring and engine client SDK for Cymule
The npm package @cymule/sdk receives a total of 11 weekly downloads. As such, @cymule/sdk popularity was classified as not popular.
We found that @cymule/sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.