
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
Official CLI for Frihet. Manage your business from the terminal.
npm install -g frihet
Or use directly:
npx frihet status
frihet login
# Enter your API key from https://app.frihet.io/settings/security
Or set the environment variable:
export FRIHET_API_KEY=fri_...
frihet status
# Revenue: EUR 15,200.00
# Expenses: EUR 3,400.00
# Net: EUR 11,800.00
# Overdue: 4 invoices (EUR 3,200.00)
# List invoices
frihet invoices list
frihet invoices list --status overdue
frihet invoices list --from 2026-01-01 --to 2026-03-31
# Create invoice
frihet invoices create --client "Acme Corp" --item "Consulting,10,150" --tax 21
# Create and send immediately
frihet invoices create --client "Acme" --item "Design,5,200" --send billing@acme.com
# View details
frihet invoices get inv_abc123
# Mark as paid
frihet invoices paid inv_abc123
# Send by email
frihet invoices send inv_abc123 --to billing@acme.com
# List expenses
frihet expenses list
frihet expenses list --from 2026-03-01
# Create expense
frihet expenses create --desc "Adobe Creative Cloud" --amount 59.99 --category software
# List clients
frihet clients list
frihet clients list -q "Acme"
# Create client
frihet clients create --name "Acme Corp" --email billing@acme.com --tax-id B12345678
| Variable | Description |
|---|---|
FRIHET_API_KEY | API key (overrides ~/.frihet/config.json) |
FRIHET_API_URL | Custom API base URL |
MIT
FAQs
Frihet CLI — manage your business from the terminal
The npm package frihet receives a total of 11 weekly downloads. As such, frihet popularity was classified as not popular.
We found that frihet demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.