
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
The unscoped `bourdon` CLI — a thin, Apache-2.0 dispatch over the @getbourdon/* engine packages. Faithful command-for-command port of cli/main.py (argparse → commander.js): ~32 top-level nodes / ~78 subparsers, the non-obvious argparse defaults copied exa
The unscoped bourdon command-line interface — a thin, Apache-2.0 dispatch
layer over the @getbourdon/* engine packages. It contains no engine logic: every
subcommand delegates to a ported @getbourdon/* package, so the CLI itself is
permissively licensed even though the engine packages are BUSL-1.1.
npx bourdon --help
# or
npm i -g bourdon && bourdon serve
This is a faithful command-for-command port of the Python cli/main.py (argparse,
~78 subparsers) to commander.js. Python (pip install bourdon) is the oracle.
Commands backed by an already-ported package run natively:
prepare-turn, deeper-context, codex compile-turn — recognition context
(@getbourdon/federation + @getbourdon/mcp-server + @getbourdon/inference)recognition eval — the scoring harness (@getbourdon/recognition)serve — the L6 federation MCP server (@getbourdon/mcp-server), including the
non-loopback-bind refusalagent {add,list,rotate,set-tier}, grant, ungrant, revoke,
staging {list,promote,reject}, audit — trust + audit (@getbourdon/federation)audit-leaks — the leak auditor (@getbourdon/redaction)agents — the --json desktop-tray contract (local enumeration)doctor, export-all, hermes {export,doctor}, claude-code export —
the participant layer (@getbourdon/participants)Commands whose backing reader is not yet ported to TS keep their full parser
surface (so bourdon --help stays complete) but exit non-zero with a pointer to the
Python implementation rather than silently failing — e.g. the cursor / copilot /
cascade export readers, the sync rsync seam, and the benchmark python seam.
The non-obvious argparse defaults are copied exactly: serve --port 7500 --host 127.0.0.1, --max-items 6 / --max-chars 1800 (but 1 / 500 on the
codex hook), --max-sessions 20, --max-entities 100, recognition eval --min-*-f1 0.0, audit --limit 50, and the access-level default split (team
everywhere except demo and sync push, which default to public).
Apache-2.0. See LICENSE.
FAQs
The unscoped `bourdon` CLI — a thin, Apache-2.0 dispatch over the supported @getbourdon/* TypeScript engine surface, including recognition, federation, participant export, leak audit, and the agents tray contract.
The npm package bourdon receives a total of 57 weekly downloads. As such, bourdon popularity was classified as not popular.
We found that bourdon demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.