This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+8 more
Summary
AI summaryAdded star prompt on first import and post‑install GitHub star nudge.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Star prompt printed to stderr on first import, with ~/.pompelmi/.starred marker. Star prompt printed to stderr on first import, with ~/.pompelmi/.starred marker. Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Feature | Medium |
`scripts/postinstall.js` prints GitHub star nudge after `npm install` in interactive terminals. `scripts/postinstall.js` prints GitHub star nudge after `npm install` in interactive terminals. Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Dependency | Medium |
`package.json` added postinstall script pointing to scripts/postinstall.js; bumped version to 1.20.0. `package.json` added postinstall script pointing to scripts/postinstall.js; bumped version to 1.20.0. Source: llm_adapter@2026-05-21 Confidence: high |
— |
Full changelog
Added
- Star prompt printed to stderr on first import (skipped in CI and non-TTY environments), with a
~/.pompelmi/.starredmarker so it shows only once. scripts/postinstall.js— prints a GitHub star nudge to stdout afternpm installin interactive terminals.
Changed
package.json— addedpostinstallscript pointing toscripts/postinstall.js; bumped version to 1.20.0.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Pompelmi
Open-source file upload security for Node.js. Scan files before storage to detect malware, MIME spoofing, and risky archives.
Related context
Related tools
Beta — feedback welcome: [email protected]