
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@sylphx/locus
Advanced tools
Locus is now repomap. This package is a thin alias of @sylphx/repomap (same MCP server and CLI).
Locus is now repomap — a map of your codebase for AI agents: code graph, hybrid search, call paths and change impact, with an interactive graph UI.
This package is a thin alias that installs @sylphx/repomap and runs it, so existing configs keep working. New installs should use:
npx -y @sylphx/repomap setup
Old tool names (architecture_*, codebase_search) are still accepted by the server until repomap 2.0.
FAQs
Locus is now repomap. This package is a thin alias of @sylphx/repomap (same MCP server and CLI).
We found that @sylphx/locus demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.