
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
@decionis/presence-node
Advanced tools
Presence SDK — verify human presence before consequential actions execute.
Applications send intent and context. Presence verifies the person. Decionis decides whether execution proceeds.
npm install @decionis/presence-node
export PRESENCE_API_KEY='presence_sk_…'
import { randomUUID } from "node:crypto";
import { PresenceClient } from "@decionis/presence-node";
const presence = new PresenceClient({
baseUrl: process.env.PRESENCE_API_URL ?? "https://presence.decionis.com",
apiKey: process.env.PRESENCE_API_KEY,
});
const result = await presence.runSandboxScenario("allow", `quickstart-${randomUUID()}`);
console.log(result.policy_verdict);
The fixture is signed with evidence_class: sandbox_fixture and always runs in Shadow
Mode. Tenant credentials belong on trusted servers only.
Application
↓
Intent + Context
↓
Presence
↓
Biometrics
↓
Liveness
↓
Presence Record
↓
Decionis Verdict
↓
Continue
Every Presence Check produces a signed Presence Record — portable evidence of who approved what, where, when, and on which device.
Install
↓
Configure
↓
Send Intent
↓
Receive Presence Result
↓
Verify Signature
↓
Done
Five minutes: docs/quickstart.md.
Wire Transfer
Treasury
Password Reset
Executive Meeting
Vendor Change
AI Approval
| Example | What it proves |
|---|---|
| simple | Your first Presence Check. |
| banking | A wire transfer with a verified Presence Record. |
| zoom | An executive meeting instruction held for review. |
| treasury | A treasury wire read through Shadow Mode enforcement. |
Product documentation lives at presence.decionis.com.
Apache-2.0. Use of the hosted Presence service is governed separately.
FAQs
Official server-side Node.js SDK for the Presence verification API.
The npm package @decionis/presence-node receives a total of 86 weekly downloads. As such, @decionis/presence-node popularity was classified as not popular.
We found that @decionis/presence-node demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.