
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
@deepseek-ai/cordis-plugin-hmr
Advanced tools
Hot module replacement for loader-managed Cordis plugins.
The HMR plugin watches source files, traces Node's module graph, clears affected
module caches, and reloads only the plugin entries that depend on changed
application files. Changes to framework-level dependencies fall back to
loader.exit(), letting the host process restart.
Module watches canonicalize their existing base directory before opening Chokidar. Exact config watches likewise canonicalize the deepest existing ancestor, then restore any missing suffix. Callbacks and diagnostics retain the requested absolute filename, while the native backend receives one filesystem spelling even when Windows supplied an 8.3 alias.
@cordisjs/plugin-loader@cordisjs/plugin-timer- id: timer
name: '@cordisjs/plugin-timer'
- id: hmr
name: '@cordisjs/plugin-hmr'
config:
root:
- src
ignored:
- '**/node_modules'
- '**/.*'
debounce: 100
| Field | Description |
|---|---|
base | Optional base directory resolved from ctx.baseUrl. |
root | Chokidar roots to watch. Defaults to ['.']. |
ignored | Picomatch patterns excluded from watch and reload analysis. |
debounce | Milliseconds to wait before processing a burst of changes. |
| Event | Description |
|---|---|
hmr/change | Emitted for changed files that are not handled by plugin reload or config reload. |
hmr/reload | Emitted after one or more plugin entries are reloaded. |
FAQs
Hot Module Replacement Plugin for Cordis
We found that @deepseek-ai/cordis-plugin-hmr demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.