
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@project-bourne/mcp
Advanced tools
Plan and execute reproducible scientific and engineering workloads across local compute, GPUs, Slurm, and PBS with preserved experiment provenance, artifacts, lineage, telemetry, and verification.
@project-bourne/mcpPlan and execute reproducible scientific and engineering workloads across local compute, GPUs, Slurm, and PBS with preserved experiment provenance, artifacts, lineage, telemetry, and verification. This zero-runtime-dependency package launches the canonical local Project Bourne MCP server:
npx -y @project-bourne/mcp
It requires Node.js 22 or newer. It first looks for Python 3.10+ with the exact
compatible bourneprov version and MCP extra. If unavailable, it may install
that exact runtime into a private, versioned user cache. It never installs into
the active project, virtual environment, Conda environment, or system Python.
Use --no-bootstrap to require an existing compatible runtime, or --doctor
to print compatibility diagnostics without bootstrapping or launching MCP.
The package only locates and launches python -m bourneprov mcp. Planning,
execution, schedulers, provenance, telemetry, and verification remain in the
Python Bourne core.
The canonical official MCP Registry identity is
io.github.KozakHou/project-bourne. Registry publication follows the matching
final npm release; the release candidate is not published to the Registry.
FAQs
Plan and execute reproducible scientific and engineering workloads across local compute, GPUs, Slurm, and PBS with preserved experiment provenance, artifacts, lineage, telemetry, and verification.
We found that @project-bourne/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.