
Security News
AI Agent Lands PRs in Major OSS Projects, Targets Maintainers via Cold Outreach
An AI agent is merging PRs into major OSS projects and cold-emailing maintainers to drum up more work.
The design doc for The npm Registry CouchApp
You need CouchDB version 1.4.0 or higher. 1.5.0 or higher is best.
Once you have CouchDB installed, create a new database:
curl -X PUT http://localhost:5984/registry
You'll need the following entries added in your local.ini
[couch_httpd_auth]
public_fields = appdotnet, avatar, avatarMedium, avatarLarge, date, email, fields, freenode, fullname, github, homepage, name, roles, twitter, type, _id, _rev
users_db_public = true
[httpd]
secure_rewrites = false
[couchdb]
delayed_commits = false
Clone the repository if you haven't already, and cd into it:
git clone git://github.com/npm/npmjs.org
cd npmjs.org
Now install the stuff:
npm install
Sync the ddoc to _design/scratch
npm start \
--npmjs.org:couch=http://admin:password@localhost:5984/registry
Next, make sure that views are loaded:
npm run load \
--npmjs.org:couch=http://admin:password@localhost:5984/registry
And finally, copy the ddoc from _design/scratch to _design/app
npm run copy \
--npmjs.org:couch=http://admin:password@localhost:5984/registry
Of course, you can avoid the command-line flag by setting it in your ~/.npmrc file:
_npmjs.org:couch=http://admin:password@localhost:5984/registry
The _ prevents any other packages from seeing the setting (with a
password) in their environment when npm runs scripts for those other
packages.
To replicate the registry without attachments, you can point your CouchDB replicator at https://skimdb.npmjs.com/registry. Note that attachments for public packages will still be loaded from the public location, but anything you publish into your private registry will stay private.
To replicate the registry with attachments, you can point your CouchDB replicator at https://fullfatdb.npmjs.com/registry.
With the setup so far, you can point the npm client at the registry by putting this in your ~/.npmrc file:
registry = http://localhost:5984/registry/_design/app/_rewrite
You can also set the npm registry config property like:
npm config set \
registry=http://localhost:5984/registry/_design/app/_rewrite
Or you can simple override the registry config on each call:
npm \
--registry=http://localhost:5984/registry/_design/app/_rewrite \
install <package>
To be snazzier, add a vhost config:
[vhosts]
registry.mydomain.com:5984 = /registry/_design/app/_rewrite
Where registry.mydomain.com is the hostname where you're running the
thing, and 5984 is the port that CouchDB is running on. If you're
running on port 80, then omit the port altogether.
Then for example you can reference the repository like so:
npm config set registry http://registry.mydomain.com:5984
FAQs
The npmjs.org registry couchapp
We found that npmjs.org demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
An AI agent is merging PRs into major OSS projects and cold-emailing maintainers to drum up more work.

Research
/Security News
Chrome extension CL Suite by @CLMasters neutralizes 2FA for Facebook and Meta Business accounts while exfiltrating Business Manager contact and analytics data.

Security News
After Matplotlib rejected an AI-written PR, the agent fired back with a blog post, igniting debate over AI contributions and maintainer burden.