
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@opentag/local-runtime
Advanced tools
Local OpenTag runtime helpers used by @opentag/cli.
Use this package when embedding the same local dispatcher, daemon, diagnostics, and GitHub PR helpers that the CLI uses.
pnpm add @opentag/local-runtime
startDispatcher: starts the local dispatcher with the unified delivery
producer and provider registry.serveDaemon: starts the local daemon loop.createDaemonRuntimeInput: derives daemon runtime input from config.runDoctor: checks dispatcher, bindings, checkouts, and executors.parseDaemonConfig: parses daemon config with compatibility aliases.maybeCreatePullRequest: creates GitHub pull requests from prepared run branches.Subpath exports are also available:
import { startDispatcher } from "@opentag/local-runtime/dispatcher";
import { serveDaemon } from "@opentag/local-runtime/daemon";
import { runDoctor } from "@opentag/local-runtime/doctor";
This package is the local runtime boundary for the CLI. Keep app wrappers thin and put reusable local runtime behavior here.
FAQs
Local OpenTag dispatcher, daemon, and diagnostics runtime helpers.
The npm package @opentag/local-runtime receives a total of 0 weekly downloads. As such, @opentag/local-runtime popularity was classified as not popular.
We found that @opentag/local-runtime demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.