
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@workflow/core
Advanced tools
Core runtime package for Workflow SDK.
Hook registration acknowledgements and token conflicts participate in replay
delivery ordering alongside step results, hook payloads, and sleep completions.
Concurrent branches awaiting hook.getConflict() preserve their step correlation
IDs when replaying an extended event history.
Failed-run logs include underlying error causes and codes to help diagnose failures such as socket, DNS, and TLS errors. Unreadable causes are marked without preventing the run from being recorded as failed.
Queued step messages carry immutable run identity in runContext, so step
execution skips the initial runs.get and fetches the run row only when
continuing into workflow replay. Messages from older producers without
runContext retain the initial fetch.
When a World advertises capabilities.invoke, resumeHook() sends serialized
hook inputs through world.invoke() and waits for the executor's decision. The
World calls the existing handler with invoke: true, requestId, and the hook
input. Core validates the input, waits for its event write, and returns a
decision. Core shares a run's activity state between workflow execution and these
input calls.
The event write completes before the response is stored. On Worlds with
hookResumeDedup, a stable request identity makes retries reuse the same hook
event, including after hook disposal or run completion. Core can process inputs
while inline steps wait. Workflow code observes committed inputs at replay
boundaries, reusing a retained Node virtual machine when available.
Errors returned by the executor propagate through world.invoke() to the caller
of resumeHook().
Register onRunCompleted and onRunFailed handlers with registerLifecycleHooks
from workflow/api for best-effort reporting of terminal transitions written by
your app. Handlers receive the workflow name without a backend read, a lazy Run
instance, and, for failures, an error hydrated from the persisted payload.
Callbacks are not retried; the event log remains the system of record.
FAQs
Core runtime and engine for Workflow SDK
The npm package @workflow/core receives a total of 1,437,551 weekly downloads. As such, @workflow/core popularity was classified as popular.
We found that @workflow/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.