
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@devframes/plugin-messages
Advanced tools
Devframe plugin for browsing, filtering, and dismissing the hub message feed.
[!WARNING] Experimental This plugin is experimental and may change without a major version bump until it stabilizes.
A devframe plugin that surfaces the hub message feed (ctx.messages) as a
portable panel: browse diagnostics and notifications from every mounted tool,
filter by level / source / category / label, inspect stack traces, element and
file positions, and jump to the offending file in your editor.
Ported from the built-in Messages view of
vitejs/devtools; rebuilt on devframe's
framework-neutral client (connectDevframe) with a Vue + Vite SPA, reading the
feed through @devframes/hub's listSince delta API.
import createMessagesDevframe from '@devframes/plugin-messages'
await hubContext.install(createMessagesDevframe())
The hub's ctx.messages host feeds the panel live — every
ctx.messages.add(...) from any mounted tool shows up, updates stream over
the devframe:messages:updated broadcast, and dismissals write back through
the plugin's namespaced RPCs. On a plain (non-hub) context the plugin warns
(DP_MESSAGES_0001) and serves an empty feed.
import { mountMessages } from '@devframes/plugin-messages/client'
const handle = await mountMessages(document.querySelector('#panel')!, {
rpc, // optional — reuse the host page's client
})
pnpx @devframes/plugin-messages
pnpm dev in this package self-hosts the SPA against a demo-seeded messages
host, so the feed is lively without a full hub.
FAQs
Devframe plugin for browsing, filtering, and dismissing the hub message feed.
The npm package @devframes/plugin-messages receives a total of 59,166 weekly downloads. As such, @devframes/plugin-messages popularity was classified as popular.
We found that @devframes/plugin-messages demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.