
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@readystack/base-image-eol-lint
Advanced tools
Marks every base image in your Dockerfiles, compose files and CI workflows whose security patches have already stopped - or stop before 13 November 2026 - and prints the tag that replaces it.

Marks every base image in your Dockerfiles, compose files and CI workflows whose security patches have already stopped - or stop before 13 November 2026 - and prints the tag that replaces it.
npx @readystack/base-image-eol-lint file
Node 18+. The same 21 rules as the VS Code extension, from a terminal or CI.
--rules lists every rule@readystack/base-image-eol-lint --dir ./templates --report html --out report.html
Snyk's Team tier is $25 per contributing developer per month.
Claude Code · Cursor · Windsurf · any MCP client - add to your MCP config:
{ "mcpServers": { "base-image-eol-lint": { "command": "npx", "args": ["-y", "@readystack/base-image-eol-lint", "--mcp"] } } }
Tools: check_text and check_file (free) · check_dir (licence). The agent gets every finding with the line number.
- name: Base Image EOL Lint - Dockerfile and CI end-of-life check
run: npx -y @readystack/base-image-eol-lint --dir . --ci
(container: docker run --rm -v "$PWD:/work" getreadystack/base-image-eol-lint --dir /work --ci)
The folder sweep, reports and CI mode need one licence — one payment, no subscription. Set READYSTACK_LICENSE=<key> or run --license <key> once.
FAQs
Marks every base image in your Dockerfiles, compose files and CI workflows whose security patches have already stopped - or stop before 13 November 2026 - and prints the tag that replaces it.
The npm package @readystack/base-image-eol-lint receives a total of 150 weekly downloads. As such, @readystack/base-image-eol-lint popularity was classified as not popular.
We found that @readystack/base-image-eol-lint demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.