
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@stll/docx-core
Advanced tools
Typed OOXML/DOCX model, validation, serialization, legal-source compilation, and browser-native package projection.
A typed OOXML/DOCX document model with parsing, validation, and serialization.
The package exposes a structured document model (paragraphs, runs, tables, styles, section properties) together with the tools to produce and check DOCX packages, plus a legal-source compiler that turns a plain legal draft into that model or a finished DOCX file.
import { compileLegalSourceToDocx, validateDocxPackage } from "@stll/docx-core";
const { docx } = await compileLegalSourceToDocx(source);
const result = await validateDocxPackage(docx);
The document model types are also available from a dedicated subpath:
import type { Document, Paragraph, Run } from "@stll/docx-core/model";
bun add @stll/docx-core
. — the document model types, the legal-source compiler
(parseLegalSource, compileLegalSourceToDocument,
compileLegalSourceToDocx, validateLegalDraft), DOCX serialization
(serializeDocumentToDocx), and validation (validateDocxPackage,
validateDocumentModel, assertValidDocumentModel)../model — the document model types only.Apache-2.0
FAQs
Typed OOXML/DOCX model, validation, serialization, legal-source compilation, and browser-native package projection.
The npm package @stll/docx-core receives a total of 7,037 weekly downloads. As such, @stll/docx-core popularity was classified as popular.
We found that @stll/docx-core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.