
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@stlw/warden-hook-server
Advanced tools
HTTP hook server for Claude Code, Codex CLI, and Copilot SDK integration
Local HTTP hooks that apply Warden policy to Claude Code, Codex CLI, and Copilot SDK tool calls. The server handles session lifecycle, prompt submission, pre-tool decisions, post-tool output tagging, and an auditable ledger.
npm install @stlw/warden-hook-server @stlw/warden
startHookServer reads your PolicyConfig, defaults to port 7429, and returns the server handle:
import { startHookServer } from "@stlw/warden-hook-server";
import type { PolicyConfig } from "@stlw/warden";
const config: PolicyConfig = {
version: "2",
meta: { environment: "development", sessionApprovalRequired: false },
policies: [
{
id: "allow-reads",
description: "Allow read tools during development",
match: { tools: ["read_file", "list_directory"], environment: ["development"] },
action: "ALLOW",
},
],
};
startHookServer({ config, dbPath: ".warden/ledger.db", port: 7429 });
Set WARDEN_AUTH_TOKEN (or pass authToken) to require X-Warden-Auth on hook requests. /health remains available for readiness checks:
curl http://localhost:7429/health
For Claude Code, point its HTTP hooks at http://localhost:7429/hooks/... and include the shared-secret header. The CLI configures the same server with warden start; use that for the quickest setup.
See the public manual for the complete Claude Code settings example and OpenCode integration.
FAQs
HTTP hook server for Claude Code, Codex CLI, and Copilot SDK integration
The npm package @stlw/warden-hook-server receives a total of 397 weekly downloads. As such, @stlw/warden-hook-server popularity was classified as not popular.
We found that @stlw/warden-hook-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.