
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@fettle/core
Advanced tools
The maintenance-health grading engine behind Fettle: rules, scoring, the GitHub fetch layer, and report assembly.
pnpm add @fettle/core
import { assess, renderMarkdown } from '@fettle/core';
const report = await assess(['acme/api', 'acme/web'], { token: process.env.GITHUB_TOKEN });
console.log(report.fleet.averageScore);
console.log(renderMarkdown(report));
assess fetches, configures and scores. assessContext scores a RepoContext you
already have, with no network involved.
Full documentation, the scoring math, and the report schema: github.com/rumankazi/fettle.
FAQs
Maintenance-health grading engine: rules, scoring, and report assembly.
The npm package @fettle/core receives a total of 237 weekly downloads. As such, @fettle/core popularity was classified as not popular.
We found that @fettle/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.