
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@mearl/cloud-types
Advanced tools
Mearl 云端通信链路的共享类型与常量。
@mearl/client、cloud-server、cloud-connector 三端通过 WebSocket 互通,本包定义它们之间消息的统一协议(消息结构、心跳、缓冲区上限、各类超时默认值),确保三端对线上格式始终一致。
仅供 monorepo 内部使用。
interface CloudMessage {
id: string;
action: string;
data: Record<string, any>;
connector?: string;
browser?: string;
timeoutSec?: number;
}
interface CloudResponse {
id: string;
success: boolean;
data?: any;
error?: string;
versionWarning?: string;
}
interface HeartbeatMessage {
type: 'ping' | 'pong';
timestamp: number;
}
interface AgentHelloMessage {
type: 'agent_hello';
}
interface ConnectorHelloMessage {
type: 'connector_hello';
connectorId: string;
name: string;
version?: string;
}
isAgentHelloMessage(msg): msg is AgentHelloMessage
isConnectorHelloMessage(msg): msg is ConnectorHelloMessage
isHeartbeatMessage(msg): msg is HeartbeatMessage
isCloudMessage(msg): msg is CloudMessage
isCloudResponse(msg): msg is CloudResponse
resolveCloudConnectorSelector(connectors, selector) 按精确 ID、精确名称、唯一模糊匹配的
顺序解析 connector 目标,并区分匹配、歧义和未找到。
MAX_BUFFER_SIZE; // 10 MB,单条消息缓冲上限
DEFAULT_REQUEST_TIMEOUT; // 60s
DEFAULT_CONNECT_TIMEOUT; // 30s
DEFAULT_HEARTBEAT_INTERVAL; // 30s
DEFAULT_HEARTBEAT_TIMEOUT; // 90s
import { type CloudMessage, isCloudResponse, DEFAULT_REQUEST_TIMEOUT } from '@mearl/cloud-types';
pnpm build # tsc 编译到 dist/
pnpm dev # tsc --watch
pnpm typecheck # 仅类型检查
ISC
FAQs
Shared types for Mearl cloud communication packages
The npm package @mearl/cloud-types receives a total of 1,404 weekly downloads. As such, @mearl/cloud-types popularity was classified as popular.
We found that @mearl/cloud-types demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.