Menu

#Maintainer

26 posts

Feed·
20 of 26 posts
The Anatomy of 50 Open Source PRs: What Gets Merged, What Gets Ignored, and Why (Real Data From an AI Agent)
🖼️
0

The Anatomy of 50 Open Source PRs: What Gets Merged, What Gets Ignored, and Why (Real Data From an AI Agent)

DEV Community: github·zk0x /// ℹ️·2 days ago
#BmKnUl5T
#dev#merge#first#maintainer#hours#repos

I let an AI agent submit 50+ pull requests across open source projects in 72 hours. Here's the...

15s
Read More
Mastering Agentic Workflows in PHP: Parameter-Aware Tool Tracking (Neuron AI #566)
🖼️
0

Mastering Agentic Workflows in PHP: Parameter-Aware Tool Tracking (Neuron AI #566)

DEV Community·Valerio·20 days ago
#RKEWMxtR
#php#ai#webdev#agents#tool#maintainer

From Dev.to - php: Mastering Agentic Workflows in PHP: Parameter-Aware Tool Tracking (Neuron AI #566)

15s
Read More
The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Aren't.
🖼️
0

The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Aren't.

DEV Community·Pico·25 days ago
#E4oxi0Ca

@anthropic-ai/sdk scores HEALTHY at depth 1. At depth 2, two of its dependencies are CRITICAL: sole maintainer, 12–16M weekly downloads, no release in two years.

15s
Read More
MCPwn Is Live. We Scanned the Supply Chains of 14 MCP Servers. Here's What We Found.
🖼️
0

MCPwn Is Live. We Scanned the Supply Chains of 14 MCP Servers. Here's What We Found.

DEV Community·Pico·27 days ago
#AAuGKslk

Real CVEs, real data. We scored 14 MCP servers on behavioral supply chain risk. Every exploited server scored below 55. The supply chains are worse than the packages.

15s
Read More
How npm Behavioral Risk Scoring Works: The Methodology Behind getcommit.dev
🖼️
0

How npm Behavioral Risk Scoring Works: The Methodology Behind getcommit.dev

DEV Community·Pico·about 1 month ago
#xWy3Si9Q

npm audit answers the wrong question for supply chain risk. Here's the 5-dimension behavioral scoring system that flags structural risk before CVEs are filed — with the full math, score weights, and real examples.

15s
Read More
The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.
🖼️
0

The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.

DEV Community·Pico·about 1 month ago
#DuALWHF0

When you score @modelcontextprotocol/sdk, you get 75/100. When you score its full dependency tree to depth 2: 11 CRITICAL packages. This is the real supply chain attack surface for MCP builders.

15s
Read More
The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.
🖼️
0

The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.

DEV Community·Pico·about 1 month ago
#tIkALoEi

From Dev.to - security: The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.

15s
Read More
Three npm Disasters That Were Predictable (And What the Signals Looked Like)
🖼️
0

Three npm Disasters That Were Predictable (And What the Signals Looked Like)

DEV Community·Pico·about 1 month ago
#FQgqdMCC

We ran three real npm supply chain incidents through proof-of-commitment scoring. The structural signals were there before every attack — event-stream (2018), ua-parser-js (2021), colors.js (2022).

15s
Read More
Express depends on escape-html. It hasn't been updated since 2015.
🖼️
0

Express depends on escape-html. It hasn't been updated since 2015.

DEV Community·Pico·about 1 month ago
#zCapVQqi

96 million weekly Express installs flow through packages with a single npm token that hasn't been rotated in a decade. npm audit shows zero issues. Our tool scores two of them CRITICAL.

15s
Read More