
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
@getbourdon/federation
Advanced tools
Bourdon L6 federation — the cross-machine trust boundary (BUSL-1.1). In-memory L6Store (visibility-filtered query primitives, async-mutex commitL5, base64url cursors, Promise.allSettled peer fan-out), the single-operator trust registry (bdn_ tokens, sha25
Bourdon L6 — the cross-machine trust boundary (BUSL-1.1). The TypeScript
mirror of the Python core/l6_store.py + l6_remote.py +
federation_{registry,audit,staging}.py. Python (pip install bourdon) is the
oracle; this package asserts against the @getbourdon/conformance
fed_seed_library / tier_matrix / on_disk fixtures.
Security-critical. Every invariant below is enforced in code, not by trust — a single missed clamp leaks PRIVATE memory across machines.
L6Store — in-memory aggregator over <library>/agents/*.l5.yaml.
Visibility-filtered query primitives (listAgents, findEntity,
listRecentWork, getCrossAgentSummary, getAgentManifest,
buildRecognitionManifest), base64url pagination cursors with a stable
(date desc, agent desc) total order, exportAgents with the egress
visibility clamp + credential redaction, and the *Federated peer fan-outs
(Promise.allSettled — a dead peer never fails the local answer; peer rows
tagged peer:<name>:<agent>).commitL5 runs behind an async mutex (the Node analogue of Python's
threading.RLock): Node interleaves at every await, so a
read-modify-write-RELOAD without serialization is the P1-3 lost-update race.FederationRegistry — single-operator trust registry at
~/.bourdon/federation.yaml. bdn_ + 24-byte-hex tokens, SHA-256 hash-only
at rest, crypto.timingSafeEqual against ALL rows (constant-time, no early
exit), trust tiers, an empty Bearer authenticates nowhere, (mtimeNs, size) hot-reload staleness key, and fail-closed parse (a corrupt registry
authenticates no one).AgentIdentity + AsyncLocalStorage caller propagation
(runWithCaller / getCaller) — Python's ContextVar. Fail-closed: an
unbound caller is OPERATOR (stdio); an unknown HTTP caller is quarantined.FederationAudit — append-only JSONL, never token material,
write-failure non-fatal, microsecond-padded timestamps, Python-json.dumps
default-separator byte parity.<library>/staging/<caller>/, invisible to every read tool until promoted.enforceToolAccess + clampPeerAccess — the tier-matrix decision
logic and the ingress/egress PRIVATE clamps.RemoteL6Client — depth-1 peer client: federation_hop: 1 on every
fan-out (#139), access_level capped to ("public","team"), never
include_private: true, per-call timeout 5.0s / recognition 0.2s, and a
never-raise wrapper so one dead peer never breaks the merge.BUSL-1.1 — see LICENSE and LICENSE_FAQ.md.
FAQs
Bourdon L6 federation — the cross-machine trust boundary (BUSL-1.1). In-memory L6Store (visibility-filtered query primitives, async-mutex commitL5, base64url cursors, Promise.allSettled peer fan-out), the single-operator trust registry (bdn_ tokens, sha25
The npm package @getbourdon/federation receives a total of 8,593 weekly downloads. As such, @getbourdon/federation popularity was classified as popular.
We found that @getbourdon/federation demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.