
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
memtrust-cli
Advanced tools
npx-runnable wrapper for the memtrust agent-memory benchmark harness. Bootstraps a verified copy of Astral's uv to fetch and run memtrust from PyPI -- no Python toolchain to provision by hand.
npx-runnable wrapper for memtrust, an open agent-memory eval harness that benchmarks memory backends (MemPalace, Mem0, Zep/Graphiti, OpenViking) against real failure modes — silent write loss, contradiction handling, ranking degradation, and more.
This package does not implement memtrust itself. It bootstraps a genuine, SHA-256-verified copy of
Astral's uv for your platform, then uses it to fetch and run
the real memtrust package from PyPI — no separate Python toolchain to install by hand.
npx memtrust-cli --help
or, if installed globally:
npm install -g memtrust-cli
memtrust --help
The first run downloads memtrust from PyPI via uv tool run --from memtrust memtrust and caches
it; subsequent runs reuse the cache.
macOS (arm64/x64), Linux (arm64/x64), Windows (arm64/x64) — the matching platform binary is pulled
in automatically via optionalDependencies.
Apache-2.0
FAQs
npx-runnable wrapper for the memtrust agent-memory benchmark harness. Bootstraps a verified copy of Astral's uv to fetch and run memtrust-cli from PyPI -- no Python toolchain to provision by hand.
We found that memtrust-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.