
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
dsh-kit-webui
Advanced tools
DSH WebUI 主题商店(dsh-kit 全家桶功能包,由 dsh-kit 聚合包挂载)——全局界面调整(对所有主题生效)+ 各主题独立风格(预设/自定义),内置多套深浅色预设
DSH WebUI 主题商店(dsh-kit 全家桶功能包,由 dsh-kit 聚合包挂载)。
不替换官方主题,而是在官方 ui-theme 的公开扩展点上叠加两层能力:
ctx.theme.overrideTokens('dsh-kit-webui.global', { light, dark });ctx.theme.register({ id, colorScheme, tokens }) + ctx.theme.setTheme(id);ocean-dark / ocean-lightsakura-dark / sakura-lightforest-dark / forest-lightsettings.section,id dsh-kit-webui-themes)GET/POST /dsh-kit-webui/themes、POST /dsh-kit-webui/themes/delete~/.dsh/dsh-kit-webui/themes.jsonlocalStorage(dsh-kit-webui.themes.v1)pnpm build # host tsc + client tsdown
pnpm build:client # 仅产 lib/client.js
作为全家桶功能包,本包不声明
dsh.bundle;其 loader 行由dsh-kit的 聚合 patch 持有(避免 duplicate loader entry id)。整体开关:dsh-kit enable|disable dsh-kit-webui,或在功能商店面板点按。
FAQs
DSH WebUI 主题商店(dsh-kit 全家桶功能包,由 dsh-kit 聚合包挂载)——全局界面调整(对所有主题生效)+ 各主题独立风格(预设/自定义),内置多套深浅色预设
We found that dsh-kit-webui demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.