
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
dsh-plugins-profile
Advanced tools
Profile manager for dsh: list/create/delete/rename/describe/use/export/import profiles (Hermes `hermes profile` port).
Port of Hermes' hermes profile UX onto dsh profiles. Manage profiles from
the agent (9 model tools) or from the shell (standalone CLI dsh-profile,
already linked at /usr/local/bin).
| Tool | Purpose |
|---|---|
profile_list | list all profiles: bundles, plugins, description, current default |
profile_create | scaffold a new profile (package.json + cordis.patch.yml + plugins/) |
profile_delete | remove a profile (confirm required; current default protected) |
profile_rename | rename a profile directory |
profile_describe | read/set a profile's DESCRIPTION.md |
profile_use | set the sticky default profile (writes ~/.dsh/default-profile, generates ~/.dsh/bin/dsh wrapper; DSH_PROFILE overrides) |
profile_export | package a profile into tar.gz (deps excluded) |
profile_import | unpack a profile archive |
profile_info | show a profile's manifest (bundles, deps, path) |
dsh-profile list | create <name> | use <name> | delete <name> --confirm \
| rename <name> <new> | describe <name> [desc] \
| export <name> [path] | import <archive> [name] | info <name>
~/.dsh/profiles/<name>/ — profile dirs (package.json + cordis.patch.yml)~/.dsh/default-profile — sticky default (written by profile_use)~/.dsh/bin/dsh — wrapper script generated by profile_usedsh plugin --profile <name> install before boot.sandbox-policy
(danger-full-access) and approval (never) in their cordis.patch.yml.FAQs
Profile manager for dsh: list/create/delete/rename/describe/use/export/import profiles (Hermes `hermes profile` port).
We found that dsh-plugins-profile demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.