
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
dsh-trend-radar
Advanced tools
Ecosystem trend dashboard ('行情面板') for dsh plugins: snapshot the dsh-plugin topic and awesome list into local history, then report weekly trends — new plugins, star gainers, category heat, awesome coverage — plus keyword radar for new plugins and star sur
别人是目录,你是仪表盘。 每小时对 dsh-plugin topic 与 awesome-dsh-plugin 收录列表做一次快照(本地 JSONL 历史),然后从时间维度分析趋势:周报、新插件雷达、star 增速榜、类别热度、收录覆盖率 —— 并带一个 experimental 的 Web 面板(增长曲线、类别热度、Top 榜单)直接叠在会话输入框上方。
| 工具 | 作用 |
|---|---|
trend_snapshot | 立即采集一次快照(GitHub topic:dsh-plugin 搜索 + awesome 收录树),追加到本地历史;窗口期内自动跳过(force: true 强制) |
trend_report | 分析历史 → 周报:新增插件、star 增速榜、类别热度、awesome 覆盖率;支持 days 窗口与 keywords 过滤 |
trend_watch | 关键词订阅雷达:add/remove/list/check——新品命中或 star 突增(≥surgeStars)即报 |
dsh plugin --profile <profile> add dsh-trend-radar
| 键 | 默认 | 说明 |
|---|---|---|
dataDir | .dsh/trends | 快照与订阅的存储目录(相对宿主 fs cwd) |
staleHours | 1 | 快照新鲜度窗口(小时) |
surgeStars | 20 | 雷达的 star 突增阈值 |
githubTokenEnv | `` | 可选:GitHub token 的环境变量名(匿名 API 限流 60 次/小时,够用;设 token 更稳) |
sectionOrder | 5 | 提示词段落顺序 |
装在有 Web UI 的 profile 上时,插件把最近一次 trend_report / trend_snapshot 的仪表盘数据(增长曲线、类别热度、新增插件榜、star 增速榜)通过 session projection 推给浏览器,渲染成输入框上方的只读面板。让 Agent 跑一次 trend_snapshot 或 trend_report 面板即刷新;每次新 turn 自动清空,避免展示过期数据。
GitHub search (topic:dsh-plugin, top 100)
+ awesome-dsh-plugin git tree (data/plugins/*.yml)
↓ collectSnapshot()
.data dsh/trends/snapshots-YYYY-MM-DD.jsonl (append-only)
↓ computeReport() / deltaBetween()
trend_report (周报) · trend_watch (雷达) · trend_snapshot (增量)
lib/trends.js(增量/周报/雷达过滤/渲染)、lib/storage.js(JSONL + watch.json)、lib/github.js(采集 + 解析分离)——全部零 DSH/Cordis 依赖,可单测。lib/client.js 走 dsh-plugin-focus 同款 experimental client 模式(dsh.client manifest + session projection),待运行实例验证。node test/trends.test.mjs
MIT
trend_snapshot tool auto-skips inside the staleHours window (default 1h). There is no background timer; collection happens when a tool runs and the history is stale.githubTokenEnv (e.g. GH_T) to a token for 5000 req/h.dataDir (default .dsh/trends): append-only snapshots-YYYY-MM-DD.jsonl plus watch.json. Delete files to reset history.FAQs
Ecosystem trend dashboard ('行情面板') for dsh plugins: snapshot the dsh-plugin topic and awesome list into local history, then report weekly trends — new plugins, star gainers, category heat, awesome coverage — plus keyword radar for new plugins and star sur
The npm package dsh-trend-radar receives a total of 21 weekly downloads. As such, dsh-trend-radar popularity was classified as not popular.
We found that dsh-trend-radar demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.