
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@vercel/oidc
Advanced tools
@vercel/oidcRuntime OIDC helper methods intended to be used with your Vercel Functions
import { getVercelOidcToken } from '@vercel/oidc';
// Get token using project.json configuration
const token = await getVercelOidcToken();
// Get token with explicit project and team (supports both IDs and slugs)
const token = await getVercelOidcToken({
project: 'my-project', // or 'prj_abc123'
team: 'my-team', // or 'team_xyz789'
});
// Get token with expiration buffer (refresh if expires within 5 minutes)
const token = await getVercelOidcToken({
expirationBufferMs: 5 * 60 * 1000,
});
getVercelOidcToken(options?)Gets the current OIDC token from the request context or environment variable. Will refresh the token if expired in development.
Options:
project?: string - Project ID (prj_*) or slugteam?: string - Team ID (team_*) or slugexpirationBufferMs?: number - Buffer time in ms before expiry to trigger refresh (default: 0)getVercelOidcTokenSync()Synchronously gets the current OIDC token without refreshing. Use getVercelOidcToken() if you need automatic refresh in development.
FAQs
Runtime OIDC helpers intended for use with Vercel Functions
The npm package @vercel/oidc receives a total of 24,310,692 weekly downloads. As such, @vercel/oidc popularity was classified as popular.
We found that @vercel/oidc demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.