
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
A code factory for agent-ready GitHub issues.
Krutrimbox is a local orchestrator. It discovers Target Issues labeled ready-for-agent that have no parent issue, implements standalone Target Issues directly or walks their ordered sub-issues, delegates AFK work to fresh Sandboxed Agent sessions (Codex or Claude Code) inside Docker Sandboxes, pauses for human work when needed, and keeps the outer process in charge of GitHub state, commits, pushes, and pull requests.
The sandbox only ever reads GitHub. All writes happen on the host with your credential, so a stray agent can never mutate GitHub state — that read-only boundary is krutrimbox's core safety property.
Full documentation lives at krutrimbox.pages.dev.
npm install --global krutrimbox
kb --help
Then follow Getting Started to authenticate GitHub and your agent, set the sandbox network policy, and build the sandbox template.
kb run --issue 1 --agent codex # one explicit Target Issue
kb run --agent claude # batch mode, all eligible issues
See CONTRIBUTING.md for local development, building, testing, and how the project's decisions are recorded.
FAQs
> A code factory for agent-ready GitHub issues.
We found that krutrimbox demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.