
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
dsh-plugins-bench
Advanced tools
Agent benchmark runner for dsh: run a task set through fresh agents, score pass/fail by expectation keywords, measure duration, and produce comparison reports (evaluation gap in the ecosystem).
生态空白:dsh 生态无评测工具(官方 BENCHMARK.md 面向内核)。bench 用独立 agent 跑任务集,按期望关键词打分,产出对比报告——模型/preset 对照实验的标配。
| 工具 | 功能 |
|---|---|
bench_run | 跑 benchmark:tasks 数组或 task_file JSON;expect 关键词判 pass;报告写 ~/.dsh/bench/runs/ |
bench_list | 历史运行 |
bench_report | 查看报告 |
bench_run label=回归 tasks=[{"id":"git","task":"运行 git status 并总结","expect":["分支"]}]
bench_run task_file=/tmp/tasks.json
bench_report
FAQs
Agent benchmark runner for dsh: run a task set through fresh agents, score pass/fail by expectation keywords, measure duration, and produce comparison reports (evaluation gap in the ecosystem).
We found that dsh-plugins-bench demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.