
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@profoundlogic/hogan
Advanced tools
A maintained fork of Hogan.js by Profound Logic. Removes deprecated mkdirp usage and ensures compatibility with modern Node.js.
A maintained fork of Hogan.js by Profound Logic.
This fork removes deprecated dependencies (notably mkdirp) and ensures compatibility with modern versions of Node.js while maintaining full API compatibility with the original Hogan.js templating engine.
npm install @profoundlogic/hogan
Usage
js
Copy code
const Hogan = require('@profoundlogic/hogan');
const template = Hogan.compile('Hello {{name}}!');
console.log(template.render({ name: 'World' })); // Hello World!
Why this fork?
hogan.js is no longer maintained and depends on an outdated version of mkdirp, causing deprecation warnings in downstream packages.
This fork replaces mkdirp with native Node.js file operations and will be maintained by Profound Logic.
License & Attribution
Licensed under the Apache License, Version 2.0.
See LICENSE.
Original authors (Twitter):
Robert Sayre
Jacob Thornton
Maintained by:
Profound Logic Software, Inc.
yaml
Copy code
---
This version is **short, professional, and complete** — it has everything npm users (and the diff2html maintainer) need.
---
## 🚀 What to do next
1. Copy that **short version** into your `README.md` file.
2. Save it.
3. Commit it:
```bash
git add README.md
git commit -m "docs: simplify README for @profoundlogic/hogan"
Bump and publish:
bash
Copy code
npm version 3.0.4 -m "chore: update README and metadata (%s)"
git push --follow-tags
npm publish --access=public
FAQs
A maintained fork of Hogan.js by Profound Logic. Removes deprecated mkdirp usage and ensures compatibility with modern Node.js.
The npm package @profoundlogic/hogan receives a total of 276,276 weekly downloads. As such, @profoundlogic/hogan popularity was classified as popular.
We found that @profoundlogic/hogan demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.