
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@readystack/dora-ict-contract-clause-lint
Advanced tools
Twenty-two checks over the ICT vendor contracts in your repository - every missing Article 30 clause named, with the wording to paste in.
Twenty-two checks over the ICT vendor contracts in your repository - every missing Article 30 clause named, with the wording to paste in.
npx @readystack/dora-ict-contract-clause-lint file
Node 18+. The same 22 rules as the VS Code extension, from a terminal or CI.
--rules lists every rule@readystack/dora-ict-contract-clause-lint --dir ./templates --report html --out report.html
Outside counsel reading one ICT contract against DORA Article 30 takes two to four hours at roughly EUR 300 an hour for EU financial-regulatory work.
Claude Code · Cursor · Windsurf · any MCP client - add to your MCP config:
{ "mcpServers": { "dora-ict-contract-clause-lint": { "command": "npx", "args": ["-y", "@readystack/dora-ict-contract-clause-lint", "--mcp"] } } }
Tools: check_text and check_file (free) · check_dir (licence). The agent gets every finding with the line number.
- name: DORA Art. 30 ICT Contract Clause Lint
run: npx -y @readystack/dora-ict-contract-clause-lint --dir . --ci
(container: docker run --rm -v "$PWD:/work" getreadystack/dora-ict-contract-clause-lint --dir /work --ci)
The folder sweep, reports and CI mode need one licence — one payment, no subscription. Set READYSTACK_LICENSE=<key> or run --license <key> once.
FAQs
Twenty-two checks over the ICT vendor contracts in your repository - every missing Article 30 clause named, with the wording to paste in.
We found that @readystack/dora-ict-contract-clause-lint demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.