
Security News
pnpm 11.5 Adds Support for Recognizing npm Staged Publishes
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.
@opencode-manager/ocm-cli
Advanced tools
OpenCode Manager CLI: attach a local OpenCode TUI to a Manager-hosted repo.
OpenCode Manager CLI and plugin package.
ocm lets a local OpenCode TUI attach to repos hosted by OpenCode Manager. It
can also mirror a local git repo up to Manager or pull a Manager repo back down
to the local working tree.
pnpm add -g @opencode-manager/ocm-cli
The package exposes the ocm binary and an OpenCode plugin entrypoint. Global
installs link the binary through the package manager. Local workspace installs
also create a best-effort ~/.local/bin/ocm symlink.
ocm login <manager-url> [token]
The token is stored in macOS Keychain under the opencode-manager service. CLI
state is stored at ~/.config/opencode-manager/state.json.
If [token] is omitted, ocm login reads it from hidden TTY input or stdin.
ocm
ocm status
ocm list
ocm use <repoId|name>
ocm push [--force] [--create] [--yes]
ocm pull [--force]
ocm logout
Running ocm with no command tries to match the current git repo's origin
against ready Manager repos. If one repo matches, it attaches OpenCode to that
Manager repo. If no repo matches, it falls back to the last selected repo, then
to local opencode.
ocm use <repoId|name> selects a Manager repo, remembers it as the last repo,
and attaches OpenCode to it.
ocm push uploads the current git repo to the matching Manager repo. Use
--create to create a Manager repo when no origin match exists, and --yes to
confirm creation in non-interactive shells.
ocm pull replaces the current working tree with the matching Manager repo. It
refuses to overwrite uncommitted local changes unless --force is passed.
The package default export is an OpenCode plugin entrypoint. Importing the
plugin performs a best-effort local ocm symlink install and then returns an
empty plugin object.
import ocm from '@opencode-manager/ocm-cli'
export default [ocm]
opencode available on PATHgit and tar (with gzip support, i.e. the -z flag) available on PATHsecurity CLI for Keychain-backed token storageFAQs
OpenCode Manager CLI: attach a local OpenCode TUI to a Manager-hosted repo.
We found that @opencode-manager/ocm-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.

Security News
Federal audit finds NIST lacked a plan to clear the NVD backlog, wasted funds on duplicate work, and delayed use of CISA data.

Research
/Security News
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.