
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@opentag/github
Advanced tools
GitHub adapter helpers for OpenTag.
Use this package to turn GitHub comments into OpenTagEvent objects and to render GitHub-friendly callback text.
pnpm add @opentag/github
normalizeGitHubIssueComment: converts an issue comment payload shape into an OpenTagEvent.normalizeGitHubPullRequestReviewComment: converts a PR review comment payload shape into an OpenTagEvent.renderAcknowledgement, renderProgress, renderFinalResult: markdown text helpers for GitHub callbacks.createPullRequest: low-level GitHub REST helper for opening PRs from runner-created branches.import { normalizeGitHubIssueComment } from "@opentag/github";
const event = normalizeGitHubIssueComment({
id: String(payload.comment.id),
commentBody: payload.comment.body,
commentUrl: payload.comment.html_url,
apiCommentsUrl: payload.issue.comments_url,
issueUrl: payload.issue.html_url,
issueNumber: payload.issue.number,
owner: payload.repository.owner.login,
repo: payload.repository.name,
actorId: payload.sender.id,
actorLogin: payload.sender.login,
private: payload.repository.private,
receivedAt: new Date().toISOString()
});
if (event) {
// Send event to @opentag/client or your own OpenTag-compatible control plane.
}
fix and run commands receive write-capable permissions such as repo:write and pr:create. Review, explain, and investigate-style commands stay read/comment oriented.
Normalizer input shapes are intentionally small and provider-specific. Prefer adding optional fields over changing existing fields.
FAQs
GitHub event normalization and callback rendering for OpenTag.
The npm package @opentag/github receives a total of 17 weekly downloads. As such, @opentag/github popularity was classified as not popular.
We found that @opentag/github demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.