
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@opentag/github
Advanced tools
GitHub adapter helpers for OpenTag.
Use this package to turn GitHub comments into OpenTagEvent objects and to render GitHub-friendly callback text.
pnpm add @opentag/github
normalizeGitHubIssueComment: converts an issue comment payload shape into an OpenTagEvent.normalizeGitHubPullRequestReviewComment: converts a PR review comment payload shape into an OpenTagEvent.renderAcknowledgement, renderProgress, renderFinalResult: markdown text helpers for GitHub callbacks.createPullRequest: low-level GitHub REST helper for opening PRs from runner-created branches.import { normalizeGitHubIssueComment } from "@opentag/github";
const event = normalizeGitHubIssueComment({
id: String(payload.comment.id),
commentBody: payload.comment.body,
commentUrl: payload.comment.html_url,
apiCommentsUrl: payload.issue.comments_url,
issueUrl: payload.issue.html_url,
issueNumber: payload.issue.number,
owner: payload.repository.owner.login,
repo: payload.repository.name,
actorId: payload.sender.id,
actorLogin: payload.sender.login,
private: payload.repository.private,
receivedAt: new Date().toISOString()
});
if (event) {
// Send event to @opentag/client or your own OpenTag-compatible control plane.
}
fix and run commands receive write-capable permissions such as repo:write and pr:create. Review, explain, and investigate-style commands stay read/comment oriented.
Normalizer input shapes are intentionally small and provider-specific. Prefer adding optional fields over changing existing fields.
FAQs
GitHub event normalization and callback rendering for OpenTag.
The npm package @opentag/github receives a total of 20 weekly downloads. As such, @opentag/github popularity was classified as not popular.
We found that @opentag/github demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.