
Security News
Lovable’s OJ Rewrites Vite’s Dev Server in Rust as AI Lowers the Cost of Forking Open Source
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.
MCP server for the French RNCP / RS registers of professional certifications (France compétences open data). Local stdio server with embedded SQLite, no API key.
MCP server (stdio) for the French RNCP / RS registers of professional certifications — France compétences open data, no API key. Search, full sheets, blocs de compétences (EDOF), validity/expiry, SIRET habilitations, comparisons, recent changes.
{ "mcpServers": { "rncp": { "command": "npx", "args": ["-y", "mcp-rncp"] } } }
Requires Node ≥ 22.16 (node:sqlite with FTS5). First run downloads the data (~90 MB) into
~/.cache/mcp-rncp (Windows: %LOCALAPPDATA%\mcp-rncp), verifies its SHA-256 and refreshes weekly.
Options: --db <rncp.sqlite> (or MCP_RNCP_DB) to pin a local database, --cache-dir <dir>, --update,
--no-update, --help.
Hosted alternative (Streamable HTTP, no install): https://mcp-rncp.com/mcp.
Data: France compétences via data.gouv.fr, Licence Ouverte 2.0 — every answer cites the source and export date. Docs, tools and licence: https://github.com/ALDEBERTArnaud/mcp-rncp
FAQs
MCP server for the French RNCP / RS registers of professional certifications (France compétences open data). Local stdio server with embedded SQLite, no API key.
The npm package mcp-rncp receives a total of 31 weekly downloads. As such, mcp-rncp popularity was classified as not popular.
We found that mcp-rncp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.