
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@standardserver/shared
Advanced tools
Internal types and utilities shared across the Standard Server ecosystem
@standardserver/shared contains internal types and utilities shared across the @standardserver ecosystem — small helpers for arrays, objects, JSON, iterators, promises, queues, IDs, URIs, and more.
It has no runtime dependencies and works in any JavaScript environment. The package exists so the other @standardserver packages can share these building blocks without duplication; its API follows their needs and is not designed for direct use in applications.
Standard Server ships as a small ecosystem of packages:
| Package | Description |
|---|---|
@standardserver/core | The shared contract: types, body parsing rules, validators, and SSE helpers |
@standardserver/fetch | Fetch API adapter for browsers, workers, and other Fetch-based runtimes |
@standardserver/node | Node.js HTTP and HTTP/2 adapter |
@standardserver/fastify | Fastify adapter built on the Node.js adapter |
@standardserver/aws-lambda | AWS Lambda adapter with response streaming |
@standardserver/peer | Message-based adapter for WebSocket, MessagePort, and custom transports |
@standardserver/shared | Internal utilities shared across the ecosystem |
For the project overview and the public contract of the ecosystem, see the core documentation.
Like what we build over at middleapi? You can help keep it going through GitHub Sponsors or Open Collective. Every bit helps! 🚀
The screenshot API for developers |
MisskeyHQDecentralized microblogging SNS born on Earth |
LN Markets |
David Walsh | Robbe Vaes | Aidan Sunbury | soonoo | Kevin Porten | Denis | Christopher Kapic |
Tom Ballinger | Sam | Titoine | Igor Makowski | hanayashiki | Lev Dubinets | Kelly Peilin Chan |
Guy Ariely | Alex | Andrey Gubanov |
With thanks to 37 past sponsors who helped get us here.
Distributed under the MIT License. See LICENCE for more information.
FAQs

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.