
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
The Sellbase CLI installs and maintains Sellbase in your project, whether it is Next.js, Vite + React or any website, on top of your Supabase.
npx supabase start # or pass --supabase-url/--anon-key/--service-role-key/--db-url for a hosted project
npx sellbase create my-store --template nextjs # or --template html: a ready store to start from
npx sellbase init --yes # schema, Edge Functions, store, owner, admin, components, agent files
npx sellbase doctor # checklist with the next step for anything missing
npx sellbase upgrade --dry-run # see what a new version changes
npx sellbase upgrade # backup, migrations, functions, components (your edits are kept)
npx sellbase add product-grid cart-drawer checkout # React storefront components into your repo
npx sellbase seed ropa # example catalog: ropa, curso, consultorio, cafeteria
npx sellbase token create --name "Claude Code" # API token for an AI agent
npx sellbase mcp # MCP server over stdio (init registers it in .mcp.json)
On a local stack, init creates the store owner and writes the admin password to .env.sellbase. For hosted projects, pass --owner-email to send an invitation.
Part of Sellbase, open source commerce that lives inside your project. MIT licensed.
FAQs
Add commerce to any app your AI builds: `npx sellbase init`.
The npm package sellbase receives a total of 45 weekly downloads. As such, sellbase popularity was classified as not popular.
We found that sellbase demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.