
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
This is a pre-release of MLscript.
To install MLscript, you can use npm:
npm i mlscript
The newest version is recommended: there may be lots of bugs in the previous versions.
To watch the project directory, you can use TypeScript(recommended)/JavaScript:
import mlscript from "mlscript"
// filename: string, workDir: string, outputDir: string, tsconfig: string, commonJS: boolean, expectTypeError: boolean
mlscript.watch("./mlscript/Main.mls", "./", "./js/", "./tsconfig.json", false, true)
The path must start with ./, or it will be treated as node_modules paths.
If you need to interoperate with TypeScript, you must provide the path of tsconfig.json file.
Otherwise, it is optional.
You can choose to use CommonJS or ES modules(recommended).
Since Mlscript is still under development, type inferences are not fully supported.
If there is a type error but it is correct, please set the expectTypeError flag to true.
To get the type error messages, please check the corresponding .mlsi files in .interfaces.
For more details, you can check the demo here.
The MLscript uses git to track the file changes.
Please make sure your project locates in a git repo.
Though not necessary, we still recommend you organize the project in this structure:
.interfaces: temporary interface files generated by MLscript.mlscript: directory for MLscript files.node_modules: third-party libraries in TypeScript.ts: directory for TypeScript files.package.json and tsconfig.json should locate in the root directory.FAQs
mlscript
The npm package mlscript receives a total of 1 weekly downloads. As such, mlscript popularity was classified as not popular.
We found that mlscript demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.