
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
Safety-ranked open-source component discovery across npm, PyPI, GitHub, and Hugging Face for humans and AI agents.
Given a query like "http client", ossfind returns open-source components ranked by whether you can actually ship a product on them — a blended, explainable score of fit · license · security · maintenance health · integration effort — served through both a web UI and an MCP tool over one ranking engine.
Its core promise: never recommend ("ship") a component whose safety evidence is unsafe, missing, or ambiguous. The engine fails closed.
New here? → GETTING_STARTED.md — install, try the offline demo, go live,
and connect it to an AI agent over MCP (Claude Code / Claude Desktop / Cursor config included), in
about five minutes.
npm install
npm run typecheck && npm test # 451 tests, fully offline
npm run gates # 14 safety gates, each proven able to fail
Run the web app (offline demo mode, uses frozen fixtures):
OSSFIND_FIXTURES=1 npm run web # http://127.0.0.1:8787
By default, the web server binds exclusively to loopback (127.0.0.1).
HOST — bind host (default 127.0.0.1). Non-loopback hosts (e.g. HOST=0.0.0.0) require OSSFIND_WEB_TOKEN to be set; starting wide-open without a token is refused.PORT — server port (default 8787).OSSFIND_WEB_TOKEN — optional Bearer token requiring Authorization: Bearer <token> on /api/* endpoints.Run the MCP server (for AI agents):
OSSFIND_FIXTURES=1 npm run mcp # stdio MCP server exposing `search_components`
Drop OSSFIND_FIXTURES=1 to hit live suppliers (npm registry, ecosyste.ms, deps.dev, OSV).
ossfind searches npm (default), PyPI, crates.io (Rust), RubyGems, GitHub repositories, Hugging Face models, or
all six at once (ecosystem: "all") — one query, results from every ecosystem merged and
safety-ranked together, so you don't have to guess where the answer lives (e.g. "video generation" →
PyPI's decord, a GitHub AI-model repo, and a Hugging Face model in the same result set). Pick the
ecosystem with the web/MCP selector, the ecosystem MCP tool argument, or &ecosystem=all on
/api/search.
Discovery is federated: a FederatedDiscoverer composes multiple source adapters per query
(parallel, per-source error isolation + timeouts, results merged and deduped by id). Enrichment routes
each candidate by its own id prefix (npm:/pypi:/cargo:/rubygems:/github:/huggingface:), so a mixed batch is
enriched correctly per-source. The safety-ranking layer is the same for every source — ossfind owns
the ranking, not the corpus. GitHub and Hugging Face are what surface AI-model repos/models (diffusers,
CogVideo, …) that aren't on any package registry.
GITHUB_TOKEN in .env.local for higher rate
limits.MIT OR Apache-2.0) is handled as a choice, not a conjunction.INDEX_MAX=50000 npm run index:build # top-N PyPI packages by downloads → .cache/index/pypi.db
The index is node:sqlite FTS5 (BM25) over name/description/keywords, semantically reranked by the
embedding model. Select the discovery source with OSSFIND_PYPI_DISCOVERY=index|libraries|auto
(default auto: local index if built, else libraries.io)..env.local (LIBRARY_IO_API_KEY=…, LIBRARIES_IO_API_KEY also accepted), loaded via
node --env-file=.env.local …. Without index or key, PyPI discovery degrades to empty (never crashes).Live mode stores successful supplier responses on disk to reduce repeat requests and avoid supplier rate limits. Fixture mode remains local and does not use this cache.
OSSFIND_CACHE_DIR — cache directory (default .cache/http/).OSSFIND_CACHE_TTL — cache lifetime in seconds for discovery, license, and health data (default 3600).OSSFIND_SECURITY_TTL — cache lifetime in seconds for OSV vulnerability data (default 300).OSSFIND_CONCURRENCY — maximum concurrent upstream enrichment requests (default 4).OSSFIND_NO_CACHE=1 — disable the live-response cache.Security responses may be up to OSSFIND_SECURITY_TTL seconds stale; tune this value down when
stricter vulnerability-data freshness is required.
Supplier APIs are free but rate-limited; review each supplier's terms before commercial use.
ossfind includes an in-memory, privacy-preserving usage collector that tracks aggregate operational health and supplier rate limits.
You can inspect usage metrics at any time without sending data anywhere:
usage_stats to receive the metrics snapshot and a formatted summary of top suppliers, cache hit rates, rate-limit headroom, and latency percentiles (p50/p95).GET /api/usage to retrieve the JSON snapshot. When OSSFIND_WEB_TOKEN is set, /api/usage requires the same Authorization: Bearer <token> header as /api/search.2xx, 4xx, 5xx), 429 counts, error counts, and latest rate-limit headroom (remaining, limit, reset, retryAfter) per approved supplier host.npm, pypi, github, huggingface), verdict distribution (ship, caution, avoid), result count summary (min, max, mean), error counts, and latency percentiles (p50, p95)..cache/telemetry/install-id.0.1.0) and ISO 8601 timestamp.Remote telemetry is off by default. Absolutely no network calls are made unless both switches are explicitly set:
# Enable remote telemetry by setting BOTH switches:
export OSSFIND_TELEMETRY=1
export OSSFIND_TELEMETRY_URL="https://your-telemetry-collector.example.com/v1/metrics"
OSSFIND_TELEMETRY=1 or OSSFIND_TELEMETRY_URL is omitted, telemetry is completely inert.https://; unencrypted http:// URLs are rejected.OSSFIND_FIXTURES=1 or during automated test runs.OSSFIND_TELEMETRY (or set OSSFIND_TELEMETRY=0) or unset OSSFIND_TELEMETRY_URL.{
"installId": "c3e98db2-5b94-4f27-9c98-1092e4ab78ef",
"version": "0.1.0",
"timestamp": "2026-08-30T06:30:00.000Z",
"snapshot": {
"suppliers": {
"registry.npmjs.org": {
"requests": 14,
"cacheHits": 12,
"cacheMisses": 2,
"statusClasses": { "1xx": 0, "2xx": 2, "3xx": 0, "4xx": 0, "5xx": 0 },
"rateLimited429": 0,
"errors": 0,
"rateLimit": { "remaining": 980, "limit": 1000 }
},
"api.github.com": {
"requests": 4,
"cacheHits": 3,
"cacheMisses": 1,
"statusClasses": { "1xx": 0, "2xx": 1, "3xx": 0, "4xx": 0, "5xx": 0 },
"rateLimited429": 0,
"errors": 0,
"rateLimit": { "remaining": 58, "limit": 60, "reset": 1725000000 }
}
},
"operations": {
"searchesServed": 3,
"ecosystems": { "npm": 2, "pypi": 1, "github": 0, "huggingface": 0 },
"verdicts": { "ship": 2, "caution": 1, "avoid": 0 },
"results": { "count": 3, "total": 24, "min": 5, "max": 10, "mean": 8.0 },
"errors": 0,
"latency": { "count": 3, "p50": 18, "p95": 42, "reservoirSize": 3 }
}
}
}
discover → enrich → fit → rank, wired in src/pipeline/orchestrator.ts:
| Stage | Module | Source |
|---|---|---|
| Discover | src/adapters/discovery.ts | npm registry search |
| Enrich | src/adapters/enrichment.ts | ecosyste.ms (license/repo), deps.dev + OpenSSF Scorecard (health), OSV (vulns) |
| Fit | src/fit/embeddings.ts · src/fit/tfidf.ts | local embedding model (live) / deterministic TF-IDF (tests), both with a keyword+coverage guard |
| Rank ★ | src/ranking/rank.ts | pure, deterministic, explainable blend + verdict |
The HTTP layer is injectable (src/http/client.ts), so every test replays frozen fixtures in
fixtures/raw/ — no test touches the network.
rank() is pure and deterministic. It computes five 0–1 sub-scores, an overall 0–100, and a verdict
(ship / caution / avoid) with hard, fail-closed rules that override any high score:
avoid if critical — regardless of a future fixedIn.-or-later, +, AND/OR,
case) — can never ship.caution; the engine will not claim "no vulnerabilities" when OSV data is missing.Every result carries a non-empty, human-readable reasons[] explaining the drivers.
npm run gates)Thirteen executable gates, each mapped to the defect/decision that spawned it (see PIPELINE_LOG.md),
each proven to reject a known-bad input (not just accept a good one):
G1 contract · G2 determinism · G3 critical-CVSS fact (v3.0/v3.1/v4) · G4 license SPDX fact ·
G5 offline · G6 version-relevance fact · G7 evidence completeness · G8 federation provenance ·
G9 Python project-context honesty · G10 scaffold snippet integrity · G11 Python stub structural
honesty · G12 recipe resolution honesty · G13 adoption cannot override safety.
Every gate after G7 exists because an independent adversarial audit found a real bug that the
then-green test suite missed.
Every component has been independently audited — each audit by an agent that did not write the code — and every one found real bugs the green test suite had missed. All are fixed and gated.
AUDIT_REPORT.md — the safety layer: 5 blockers (all fixed).REAUDIT_REPORT.md — independent re-audit confirming all 5 closed.CACHE_AUDIT.md — the live cache: key-collision + stale safety signal (both fixed).FEDERATION_AUDIT.md — federation/GitHub/all-ecosystem: 2 structural holes (→ G8).AUDIT_AGENT_LAYER_A.md — npm/PyPI manifest, compat, MCP, ZIP/range: false "compatible" blocker (→ G9).AUDIT_AGENT_LAYER_B.md — scaffold + stub parser: code injection into generated snippets and
fabricated exports from docstrings (→ G10, G11).AUDIT_AGENT_LAYER_C.md — recipes + typeshed: fail-open on supplier errors, false "ready" (→ G12).Xenova/all-MiniLM-L6-v2 via
@huggingface/transformers, mean-pooled, cached per package under .cache/embeddings/) ranks by
meaning. Fixture/test mode uses deterministic TF-IDF so tests stay offline and exact. Force either
with OSSFIND_FIT=embeddings|tfidf; live falls back to TF-IDF if the model can't load.searchHybrid). It does not scale to the full ~928k
corpus by API crawl — use ecosyste.ms bulk dumps + an ANN index for that (deliberately not built).FAQs
Safety-ranked open-source component discovery across npm, PyPI, crates.io, RubyGems, GitHub and Hugging Face — for humans and AI agents. Ships an MCP server and verified API signatures so agents stop guessing.
The npm package ossfind receives a total of 53 weekly downloads. As such, ossfind popularity was classified as not popular.
We found that ossfind demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.