
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
Package-adoption dashboard for people who ship developer tools. Not yet released — this reserves the name.
Your package's adoption, on one page, on your own box.
npm, PyPI, Docker Hub and friends — read on a schedule and rendered to a static page you host yourself. No account, no database, no phone-home.
Not released yet. soundings@0.0.1 is a name reservation. It prints a notice and exits; it
does not collect anything, and nothing should be built against it.
Watch soundings.dev.
Soundings will ship proprietary and source-available: free to run against packages you publish or maintain, source readable for review and interoperability, with no right to rehost it as a service or build a competing product from it.
This placeholder is marked UNLICENSED because it grants nothing and does nothing — the real
licence ships with the first release that has software to license.
© RADLAB LLC
FAQs
Package-adoption dashboard for people who ship developer tools. Not yet released — this reserves the name.
We found that soundings demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.