
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@yafoo/art-template
Advanced tools
JavaScript Template Engine - Fork of art-template with modernized build toolchain
Fork 自 art-template
本项目是 art-template 的 fork 版本,原项目已停止维护。 本 fork 主要更新:
- 升级各种依赖
- 构建工具迁移到 Vite 8(Rolldown + Oxc)
安装:
npm install @yafoo/art-template⚠️ 声明:本人技术有限,以上改动是由AI完成的,不能保证安全及兼容问题
art-template is a simple and superfast templating engine that optimizes template rendering speed by scope pre-declared technique, hence achieving runtime performance which is close to the limits of JavaScript. At the same time, it supports both NodeJS and browser. speed test online.
art-template 是一个简约、超快的模板引擎。它采用作用域预声明的技术来优化模板渲染速度,从而获得接近 JavaScript 极限的运行性能,并且同时支持 NodeJS 和浏览器。在线速度测试。
FAQs
JavaScript Template Engine - Fork of art-template with modernized build toolchain
The npm package @yafoo/art-template receives a total of 0 weekly downloads. As such, @yafoo/art-template popularity was classified as not popular.
We found that @yafoo/art-template demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.