
Research
/Security News
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
Two Joyfill npm beta releases contain an import-time implant that uses blockchain transactions to retrieve a remote-access trojan.
@prisma-next/contract-authoring
Advanced tools
Target-agnostic contract authoring builder core for Prisma Next
Status: Phase 2 - Target-agnostic contract authoring core extracted
This package contains the target-agnostic contract authoring builder core for Prisma Next.
This package provides generic builder primitives that can be composed with target-family specific types (e.g., SQL) to create contract authoring surfaces. It is part of the authoring ring and depends only on @prisma-next/contract and core packages.
TableBuilder, ModelBuilder, ContractBuilder)@prisma-next/sql-contract-ts) to compose generic core with family-specific typesThis package was created in Phase 2 of the contract authoring extraction. It contains the extracted target-neutral builder core from @prisma-next/sql-contract-ts. The SQL layer (@prisma-next/sql-contract-ts) composes this generic core with SQL-specific types.
ColumnBuilderState, TableBuilderState, ModelBuilderState, ContractBuilderState) that don't reference any target-family specific typesTableBuilder, ModelBuilder, ContractBuilder) that handle state management@prisma-next/sql-* or other family-specific modules@prisma-next/contract - Core contract typests-toolbelt - Type utilitiesColumnBuilderState, TableBuilderState, ModelBuilderState, ContractBuilderState, RelationDefinition, ColumnBuilderTableBuilder, ModelBuilder, ContractBuilderBuildStorageColumn, BuildStorage, BuildModels, BuildRelations, extract helpers, MutabledefineContract() (generic)This package is intended for use by target-family specific authoring packages (e.g., @prisma-next/sql-contract-ts). End users should import from the target-family specific packages, not directly from this package.
@prisma-next/sql-contract-ts - SQL-specific contract authoring surface that composes this generic coreFAQs
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Two Joyfill npm beta releases contain an import-time implant that uses blockchain transactions to retrieve a remote-access trojan.

Security News
Socket releases free Certified Patches for high-severity Nuxt vulnerabilities, including server-side remote code execution through server island props.

Security News
An open letter signed by 50 companies, from NVIDIA and Microsoft to Mistral and Hugging Face, urges Washington not to restrict open weight AI.