
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@embedded-postgres/darwin-arm64
Advanced tools
A package containing the Postgres binaries for a particular architecture and operating system. See the embedded-postgres package.
This package contains the darwin-arm64 Postgres binaries for use with the embedded-postgres
package. See
embedded-postgres for a more
developer-friendly way of spawning PostgresQL clusters.
embedded-postgres is available from NPM:
npm i embedded-postgres
If you just want to use the binaries, you can also just use this package
directly. It exports the paths to the
pg_ctl,
initdb and
postgres binaries
for darwin-arm64.
npm i @embedded-postgres/darwin-arm64
Follow the documentation to discover how to interface with the binaries. Any implementation is going to look something like this:
import { pg_ctl, initdb, postgres } from '@embedded-postgres/darwin-arm64'
import { execSync, spawn } from 'child_process';
execSync(initdb);
spawn(postgres);
[!IMPORTANT]
A more friendly wrapper for using these binaries is provided as the embedded-postgres package. Please use it if you're confused by the binaries.
Embedded Postgres was created by Lei Nelissen for BMD Studio. It is based on zonky's embedded-postgres-binaries. The binaries are made available under the Apache License 2.0, whereas the specific code in this package is made available under the MIT license.
FAQs
A package containing the Postgres binaries for a particular architecture and operating system. See the embedded-postgres package.
The npm package @embedded-postgres/darwin-arm64 receives a total of 12,648 weekly downloads. As such, @embedded-postgres/darwin-arm64 popularity was classified as popular.
We found that @embedded-postgres/darwin-arm64 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.