
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@opentag/store
Advanced tools
SQLite and Drizzle persistence primitives for OpenTag.
Use this package when embedding the dispatcher, testing dispatcher behavior, or building a compatible control plane that wants OpenTag's default run storage and lease model.
pnpm add @opentag/store
migrateSchema: creates or updates the SQLite schema.createOpenTagRepository: repository API for runners, bindings, runs, leases, progress, completion, factory recipes/workstreams, replay-safe batch receipts, and audit events.schema.ts.ClaimedOpenTagRun, OpenTagAuditEvent, RepoBinding, ChannelBinding, and SlackChannelBinding.import Database from "better-sqlite3";
import { drizzle } from "drizzle-orm/better-sqlite3";
import { createOpenTagRepository, migrateSchema } from "@opentag/store";
const sqlite = new Database("opentag.db");
migrateSchema(sqlite);
const repo = createOpenTagRepository(drizzle(sqlite));
await repo.registerRunner({ runnerId: "runner_local", name: "Local Runner" });
await repo.createRepoBinding({
provider: "github",
owner: "acme",
repo: "demo",
runnerId: "runner_local"
});
The repository methods are public API for embedded control planes. The raw Drizzle table definitions are lower-level and may evolve with migrations.
FAQs
SQLite and Drizzle persistence primitives for OpenTag runs and leases.
The npm package @opentag/store receives a total of 0 weekly downloads. As such, @opentag/store popularity was classified as not popular.
We found that @opentag/store demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.