
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
Harper is an open-source Node.js performance platform that unifies database, cache, application, and messaging layers into one in-memory process.
Harper is an open-source Node.js unified development platform that fuses database, cache, application, and messaging layers into one in-memory process. With Harper you can build ultra-high-performance services without boilerplate code and scale them horizontally.
Key Features:
Unified Runtime: Database, cache, application logic, and messaging all operate within a single in-memory Node.js process, eliminating external dependencies and reducing latency.
In-Memory Performance: Data and compute share memory space for microsecond-level access times and exceptional throughput under load.
Native Messaging: Built-in publish/subscribe messaging with Websockets and MQTT enables real-time communication between nodes and clients without external brokers.
Developer Simplicity: Annotate your data schema with @export to instantly generate REST APIs. Extend functionality by defining custom endpoints in JavaScript.
Deploy with Harper Fabric for Horizontal Scalability: Distribute workloads across multiple Harper nodes by selecting your regions and latency targets.
npm i -g harper
Get started building Harper applications by following our Learn guide: https://docs.harperdb.io/learn
Harper's open source core accepts contributions from the community! Please read our guidelines before contributing.
Open an issue if you find a bug, or reach out on our Discord if you have questions or want to discuss ideas.
For more information on how to contribute, please see our:
Harper Pro is the source-available distribution of Harper, built on top of this open source harper core. It extends the core with enterprise features including multi-node replication, certificate management, and extended profiling and analytics. It is licensed under the Elastic License 2.0.
HarperDB is our previous name. Earlier in 2025, we rebranded to just "Harper" to reflect our evolution from a database to a full performance platform. The core technology remains the same, but we've expanded our vision to encompass more than just database functionality. Since this repo was created from the existing Harper codebase, you may still see references to the old name "HarperDB" in certain places.
Please review our Security Policy for reporting vulnerabilities.
Please always disclose vulnerabilities privately to security@harperdb.io before making them public.
Harper is available under the Apache-2.0 License. See the LICENSE for the full license text or the License FAQ for more information.
FAQs
Harper is an open-source Node.js performance platform that unifies database, cache, application, and messaging layers into one in-memory process.
The npm package harper receives a total of 12,862 weekly downloads. As such, harper popularity was classified as popular.
We found that harper demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.