
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@postman/cloud-agent-worker
Advanced tools
Runs Postman Cloud Agent tasks inside your own network, so the agent can reach self-hosted git and other private services.
Runs Postman Cloud Agent tasks inside your own network, so the agent can work with a self-hosted git provider and other services Postman's cloud cannot reach.
Your git credentials stay on your machine. Postman never receives them.
Node 22+ and Docker. Every task runs in its own container.
npm install -g @postman/cloud-agent-worker
Create ~/.postman-worker/config.json:
{
"postmanAccessToken": "<your Postman access token>",
"git": {
"provider": "gitlab",
"host": "https://gitlab.internal.example.com",
"token": "<your GitLab access token>"
}
}
postman-cloud-agent-worker start
The worker only makes outbound connections — no ports to open, nothing to expose. It logs
Registered with orchestrator — polling for work once it is ready.
Run it under systemd, Docker, or your usual process supervisor. You can run several sharing the same config; tasks are spread across them.
postman-cloud-agent-worker --help # every setting and environment variable
WORKER_LOG_LEVEL=debug postman-cloud-agent-worker start
debug traces every call the worker makes — URL, status, elapsed time — which is usually
enough to tell a bad token from an unreachable host.
FAQs
Runs Postman Cloud Agent tasks inside your own network, so the agent can reach self-hosted git and other private services.
The npm package @postman/cloud-agent-worker receives a total of 8 weekly downloads. As such, @postman/cloud-agent-worker popularity was classified as not popular.
We found that @postman/cloud-agent-worker demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.