
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@mocito/install-telemetry
Advanced tools
Best-effort, once-per-version install telemetry for Node.js tools.
A small, runtime-agnostic helper for optional install/update telemetry in Node.js tools. It reports each tool version at most once, retries after failed requests, and prevents duplicate reports from concurrent processes.
The library owns telemetry mechanics. The application owns its tool name, version, state location, and opt-out policy:
import { reportInstallTelemetry } from "@mocito/install-telemetry";
void reportInstallTelemetry({
endpoint: "https://telemetry.example.com/api/report-install",
tool: "my-tool",
version: "1.2.3",
statePath: "/home/user/.local/state/my-tool/install-telemetry.json",
enabled: process.env.CI !== "true",
});
Use a user-private state path. Do not pass prompts, credentials, paths, or other user data as tool or version.
tool, version, and a bounded runtime User-Agent.enabled is false or metadata fails the server-safe format checks.The endpoint is required, must use HTTPS, and cannot contain credentials or a fragment. The timeout is intentionally fixed. Tests can inject fetch without changing production routing.
FAQs
Best-effort, once-per-version install telemetry for Node.js tools.
The npm package @mocito/install-telemetry receives a total of 190 weekly downloads. As such, @mocito/install-telemetry popularity was classified as not popular.
We found that @mocito/install-telemetry demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.