
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@openai/create-sites
Advanced tools
@openai/create-sitesCreate ChatGPT Sites projects.
npm create @openai/sites@latest my-site
npm create @openai/sites@latest my-site -- --yes --add-ons d1,r2
pnpm create @openai/sites@latest my-site --yes --add-ons d1,r2
Use --yes for noninteractive generation. Dependencies are not installed by
default; pass --install to install them. The d1 add-on adds a D1 binding and
Drizzle, r2 adds an R2 binding, and auth adds ChatGPT authentication helpers.
npx --yes @openai/create-sites@latest . \
--yes --add-ons d1,r2
The generated .openai/hosting.json is the source of truth for Sites bindings.
ChatGPT Sites manages deployed databases and buckets; the initializer does not
provision resources or initialize a Git repository.
This package is licensed under the MIT License.
FAQs
Create ChatGPT Sites projects.
The npm package @openai/create-sites receives a total of 145,914 weekly downloads. As such, @openai/create-sites popularity was classified as popular.
We found that @openai/create-sites demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 18 open source maintainers collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.