
Research
/Security News
npm Author Qix Compromised via Phishing Email in Major Supply Chain Attack
npm author Qix’s account was compromised, with malicious versions of popular packages like chalk-template, color-convert, and strip-ansi published.
This is the NLP Engine for ChatFAQ. It is divided in two modules:
The Retriever is the main class for the information retrieval system. It takes as input a question (query) and a context and returns the most relevant sentences from the context to the query. This is done using embeddings and the dot product to compute the similarity between the query and the context sentences.
The RetrieverAnswerer is the main class for the chatbot. It takes as input a question (query) and a context and returns a response to the query. This is done by first retrieving the most relevant sentences from the context to the query and then generating a response based on the retrieved sentences.
add repository to poetry config
poetry config repositories.test-pypi https://test.pypi.org/legacy/
get token from https://test.pypi.org/manage/account/token/
store token using
poetry config pypi-token.test-pypi pypi-YYYYYYYY
get token from https://pypi.org/manage/account/token/
store token using
poetry config pypi-token.chat-rag pypi-XXXXXXXX
Each time you need to publish
Bump version
poetry version prerelease
or
poetry version patch
Then build
poetry build
To TestPyPi
poetry publish -r test-pypi
To PyPi
poetry publish
FAQs
Unknown package
We found that chat-rag demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
npm author Qix’s account was compromised, with malicious versions of popular packages like chalk-template, color-convert, and strip-ansi published.

Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.

Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.