Mastra npm packages added easy-day-js malware, exposing developer systems and CI runners to infostealer risks.
Six Proto6 flaws in protobuf.js enable RCE and DoS attacks; patched in versions 7.5.6 and 8.0.2 to protect Node.js services.
A community building flexible open source tools for GraphQL. Open-source GraphQL tools for modern API development: client libraries, server frameworks, and AI agent integration (MCP Server). Used by ...
The npm package has a module field pointing to an ES module variant of the library, mainly to provide support for ES module aware bundlers, whereas its browser field points to an UMD module for full ...