
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@livewiki/cli
Advanced tools
livewiki command-line interface — living documentation anchored to code, verifiable against hallucination.
The livewiki command — living repository documentation, anchored to code
and verifiable against hallucination.
Full guide, philosophy, and benchmarks: github.com/eduardoabreu81/livewiki
Requires Node.js 24 or newer.
npm install -g @livewiki/cli
(or prefix every command with npx @livewiki/cli)
livewiki init # index the repo + create the wiki layout (zero tokens)
livewiki install # wire your agent (MCP server, hooks, skill) — optional
livewiki status # open documentation debt, risk-ranked
livewiki verify # anti-hallucination gate — exits non-zero on any issue
livewiki view # self-contained offline site with search and Mermaid
Writing docs can be done two ways: your own agent in-session (no extra
API key — livewiki install sets it up), or an unattended full-repo run
(livewiki init --batch with a provider preset in
.livewiki/config.json and the key in an env var). Both produce the same
wiki and mix freely.
@livewiki/mcp — MCP
server for any MCP client (Claude Code, Cursor, Codex, …)@livewiki/core — the
library underneath: indexer, anchors, ledger, pipelineMIT
FAQs
livewiki command-line interface — living documentation anchored to code, verifiable against hallucination.
The npm package @livewiki/cli receives a total of 32 weekly downloads. As such, @livewiki/cli popularity was classified as not popular.
We found that @livewiki/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.