
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
@fedify/vocab-tools
Advanced tools
This package contains the utilities for working with Activity Vocabulary objects, which are auto-generated from the IDL.
deno add @fedify/vocab-tools
npm install @fedify/vocab-tools
pnpm add @fedify/vocab-tools
yarn add @fedify/vocab-tools
Run development tasks from the repository root with mise.
The code generator has separate output snapshots for Deno, Node.js, and Bun. When a change affects generated output, update all three from the repository root:
mise run test:update_snapshots
Review and commit every changed snapshot file. Updating only one runtime leaves the other test suites with stale expectations.
FAQs
Code generator for Activity Vocabulary APIs
The npm package @fedify/vocab-tools receives a total of 6,430 weekly downloads. As such, @fedify/vocab-tools popularity was classified as popular.
We found that @fedify/vocab-tools demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.