
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@papi-ai/shared
Advanced tools
Shared PAPI contract: the PapiAdapter interface, every entity type, business rules and markdown parsers — used by the MCP server, the pg adapter and the dashboard
Shared types and business rules for PAPI packages. Used by both the MCP server (@papi/server) and the PAPI dashboard.
TaskStatus and TaskPriority typesVALID_TRANSITIONS — state machine for task status changesnpm install @papi/shared
This package is a dependency of @papi/adapter-md and @papi/server — you typically don't need to install it directly unless you're building custom tooling on top of PAPI.
MIT
FAQs

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.