
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@upfyn/aiReusable model API contracts, provider adapters, and streaming primitives from Upfyn. The package supports isolated runtime instances; importing it does not register providers globally.
import { createLlmRuntime } from "@upfyn/ai";
import { registerBuiltInApiProviders } from "@upfyn/ai/providers";
const runtime = createLlmRuntime();
registerBuiltInApiProviders(runtime.registry);
Provider-neutral contracts, validation, diagnostics, and event streams are
available from the package root and focused subpaths such as
@upfyn/ai/event-stream, @upfyn/ai/transports, and
@upfyn/ai/validation. No second Upfyn runtime package is required.
Provider ids, credentials, model catalogs, retries, and failover remain
application concerns. Upfyn supplies those policies around this package.
Host policy (request fetch guarding, secret redaction, strict-tool defaults,
provider plugin hooks, and diagnostics logging) can be injected with
configureAiTransportHost; the defaults are inert.
The explicit @upfyn/ai/internal/anthropic, openai, retry-after,
runtime, and shared subpaths exist for the Upfyn application itself.
They carry no semver guarantee and can change or disappear in any release; do
not depend on them outside Upfyn.
FAQs
Reusable model provider adapters and streaming runtime from Upfyn
We found that @upfyn/ai demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.