
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@forestrie/merklelog
Advanced tools
MMR (merkle mountain range) proofs and massif storage format for Forestrie transparency logs
TypeScript implementation of the MMR (Merkle Mountain Range) merklelog format.
This package provides TypeScript implementations of the algorithms and data structures defined by the go-merklelog project.
The package is organized into three main modules:
pnpm add @forestrie/merklelog
import { Uint64 } from "@forestrie/merklelog";
const a = new Uint64(42);
const b = new Uint64(10);
const sum = a.add(b);
console.log(sum.toBigInt()); // 52n
import { Massif } from "@forestrie/merklelog";
const buffer = new Uint8Array(/* massif blob data */);
const massif = new Massif(buffer);
// Read fields dynamically
const lastID = massif.lastID;
const massifIndex = massif.massifIndex;
// Get complete start information
const start = massif.getStart();
// Access field by index
const field = massif.fieldref(0); // Returns 32-byte field at index 0
import { bagPeaks, verifyInclusion, Hasher } from "@forestrie/merklelog";
// Bag peaks to compute root (hasher.digest() is async)
const root = await bagPeaks(hasher, peakHashes);
// Verify inclusion proof
const isValid = await verifyInclusion(hasher, leafHash, proof, root);
This package follows the terminology defined in the term cheatsheet:
See LICENSE file in the repository.
FAQs
MMR (merkle mountain range) proofs and massif storage format for Forestrie transparency logs
We found that @forestrie/merklelog demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.