
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
openwebhook
Advanced tools
CLI público npm y servidor MCP para recibir webhooks de OpenWebhook en una aplicación local. Requiere Node.js 20.9 o posterior.
npm install --global openwebhook
Este repositorio no publica el paquete automáticamente. Para desarrollo:
cd cli
npm install
npm run build
npm test
openwebhook auth ow_live_xxx
El token se guarda en
$XDG_CONFIG_HOME/openwebhook/config.json (por defecto,
~/.config/openwebhook/config.json). El directorio usa permisos 0700 y el
archivo 0600. OPENWEBHOOK_TOKEN permite proporcionar el token sin escribir
un archivo y OPENWEBHOOK_CONFIG permite cambiar la ruta.
openwebhook listen mi-endpoint --port 3001
El CLI abre el stream SSE autenticado y reenvía cada webhook exclusivamente a
127.0.0.1:3001. Conserva método, path, query y cuerpo. Conserva los headers de
la petición salvo headers hop-by-hop, Host, Content-Length, headers proxy y
headers Forwarded/X-Forwarded-*; Host y Content-Length se recalculan.
El destino local nunca se obtiene del evento ni de la API: el host está fijado
a 127.0.0.1 y el puerto solo procede de --port. Rutas absolutas, URLs
protocol-relative, barras invertidas y saltos de línea se rechazan.
openwebhook mcp
El servidor usa JSON-RPC por stdio con @modelcontextprotocol/sdk. No escribe
logs en stdout. Expone:
list_endpointscreate_endpoint (slug)delete_endpoint (endpoint_id, obtenido con list_endpoints)watchunwatchwait_for_webhook (timeout_ms opcional, máximo 300000)watch mantiene un stream SSE y un buffer FIFO efímero, solo en memoria, de
hasta 100 eventos por endpoint. unwatch elimina ese buffer. El proceso no
persiste payloads.
Ejemplo de configuración de un cliente MCP:
{
"mcpServers": {
"openwebhook": {
"command": "openwebhook",
"args": ["mcp"],
"env": {
"OPENWEBHOOK_TOKEN": "ow_live_xxx"
}
}
}
}
OPENWEBHOOK_API_URL cambia el origen, que debe usar HTTP(S) y no puede incluir
credenciales. El valor por defecto es https://openwebhook.co.
El CLI consume este contrato:
GET /api/pro/endpointsPOST /api/pro/endpoints con {"slug":"..."}DELETE /api/pro/endpoints/:endpointIdGET /api/events/:slug con Accept: text/event-streamTodas las peticiones incluyen Authorization: Bearer <token>. Las respuestas
de endpoints pueden usar un objeto directo o las envolturas endpoints y
endpoint, respectivamente.
FAQs
Inspect webhooks on localhost without an account. Permanent slugs need OpenWebhook Pro.
The npm package openwebhook receives a total of 33 weekly downloads. As such, openwebhook popularity was classified as not popular.
We found that openwebhook demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.