
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
Themis — tech-lead lifecycle governance for DeepSeek Harness: 21 governance tools plus capability discovery (classify/state/plan/evidence/gates/release/install audits, context/evidence/progress analysis, mutation preview). No writes, no subprocesses, no n
Themis — tech-lead lifecycle governance for DeepSeek Harness: 21 governance tools + discovery (task tiering, state/plan/evidence validation, gate precheck/aggregation/reopen, release/install audits, context & progress analysis, critical path, resume reconciliation, mutation preview that always denies execution).
dsh plugin --profile headless add dsh-themis
No filesystem writes, no subprocesses, no network access — every tool computes
over caller-supplied JSON only. Inputs are budget-bounded (oversized or
unscannable payloads fail closed with INPUT_TOO_LARGE / SCAN_INCOMPLETE), and
decision tools attach deterministic guidance (nextActions with doneWhen).
Every tool accepts protocolJson to negotiate the result wire format
(bare legacy / tech-lead.result.v1 envelope / tech-lead.result.v2 default), and
canonical context snapshots (tech-lead.context v2) validate strictly or migrate
unknown keys into namespaced extensions under compat mode.
Upstream docs: https://github.com/240xu/tech-lead-skill
FAQs
Themis — tech-lead lifecycle governance for DeepSeek Harness: 21 governance tools plus capability discovery (classify/state/plan/evidence/gates/release/install audits, context/evidence/progress analysis, mutation preview). No writes, no subprocesses, no n
The npm package dsh-themis receives a total of 997 weekly downloads. As such, dsh-themis popularity was classified as not popular.
We found that dsh-themis demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.