
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
Baserun is the testing and observability platform for LLM apps.
npm install baserun
# or
yarn add baserun
Create an account at https://baserun.ai. Then generate an API key for your project in the settings tab and set it as an environment variable.
export BASERUN_API_KEY="your_api_key_here"
Baserun will automatically trace all the calls to OpenAI and Anthropic.
A simple await baserun.init() is enough to set everything up.
import OpenAI from 'openai';
import { baserun } from 'baserun';
const openai = new OpenAI({
apiKey: process.env.OPENAI_API_KEY,
});
await baserun.init();
const chatCompletion = await openai.chat.completions.create({
model: 'gpt-3.5-turbo',
temperature: 0.7,
messages: [
{
role: 'user',
content: 'What are three activities to do in Paris?',
},
],
});
Now head over to https://baserun.ai/monitoring/traces and have a look at the traces that were just created.
Baserun comes with built-in jest support, allowing you to run evaluations on your prompts, which get reported to the Baserun dashboard.
Use our Jest preset and start immediately logging to Baserun. By default all OpenAI completion and chat requests will be logged to Baserun. Logs are aggregated by test.
// test_module.spec.ts
import OpenAI from 'openai';
const openai = new OpenAI({
apiKey: process.env.OPENAI_API_KEY,
});
describe('Baserun end-to-end', () => {
it('should suggest the Eiffel Tower', async () => {
const chatCompletion = await openai.chat.completions.create({
model: 'gpt-3.5-turbo',
temperature: 0.7,
messages: [
{
role: 'user',
content: 'What are three activities to do in Paris?',
},
],
});
expect(chatCompletion.choices[0].message!.content!).toContain(
'Eiffel Tower',
);
});
});
To run the test and log to baserun:
jest --preset baserun test_module.spec.ts
...
========================Baserun========================
Test results available at: https://baserun.ai/runs/<id>
=======================================================
If you are already using a Jest preset such as ts-jest you will need to merge the presets in a Jest config
// jest.config.js or jest.config.baserun.js
const tsPreset = require('ts-jest/jest-preset');
const baserunPreset = require('baserun/jest-preset');
module.exports = {
...tsPreset,
...baserunPreset,
testTimeout: 10000,
};
Then to run a test and log to baserun:
jest test_modules.spec.ts
...
========================Baserun========================
Test results available at: https://baserun.ai/runs/<id>
=======================================================
For a deeper dive on all capabilities and more advanced usage, please refer to our Documentation.
FAQs
The Baserun TypeScript SDK
We found that baserun demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.