
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
@decantr/registry
Advanced tools
Certified vocabulary contracts, schemas, API client, and content utilities for Decantr
Support status: core-supported
Release channel: stable
Certified vocabulary contracts, schemas, API client, ranking helpers, and content utilities for Decantr.
npm install @decantr/registry
ContentHealthReport types for vocabulary supply-chain health artifactsRegistryAPIClient for server-side and tool-side registry access@decantr/registry/client for web-safe API usagepatternToDiscoveryCandidate(), scorePatternCandidate(), and rankPatternCandidates()All, Featured, Certified, and Labs registry cutsNode/runtime usage:
import { RegistryAPIClient } from '@decantr/registry';
const client = new RegistryAPIClient({ baseUrl: 'https://api.decantr.ai/v1' });
const results = await client.search({
q: 'dashboard',
type: 'blueprint',
blueprintSet: 'featured',
});
Browser-safe usage:
import { createRegistryClient } from '@decantr/registry/client';
const client = createRegistryClient({ baseUrl: 'https://api.decantr.ai/v1' });
const summary = await client.getIntelligenceSummary();
Pattern discovery usage:
import { patternToDiscoveryCandidate, rankPatternCandidates } from '@decantr/registry';
const matches = rankPatternCandidates(
{ query: 'recipe feed with avatars and infinite scroll', route: '/feed' },
patterns.map((pattern) => patternToDiscoveryCandidate(pattern)),
);
This package owns the canonical registry schemas published under @decantr/registry/schema/*, including content-health-report.v1.json for local content repository health reports emitted by decantr content-health.
Blueprint records can include blueprint_portfolio metadata. List/search summaries expose that metadata so clients can show public-facing blueprint sets without leaking internal maturity labels:
all — supported public starter-kit blueprints, excluding Labs and folded slugs by defaultfeatured — curated default discovery pickscertified — starter kits with certified artifact metadatalabs — opt-in experimental directions@decantr/registry is part of the stable public Decantr package surface in the Decantr 3 line.
@decantr/registry provides registry schemas, content utilities, and API clients. It may read explicit local registry JSON files when resolver helpers are used, and it may call the configured Decantr API base URL when client methods are invoked. It does not write files, spawn processes, emit telemetry, or upload source by itself. See security permissions.
MIT
FAQs
Legacy compatibility package for Decantr content contracts, schemas, and API client utilities
The npm package @decantr/registry receives a total of 20 weekly downloads. As such, @decantr/registry popularity was classified as not popular.
We found that @decantr/registry demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.