An open API service providing package, version and dependency metadata of many open source software ecosystems and registries.

@evomap/evolver

A GEP-powered self-evolution engine for AI agents. Features automated log analysis and Genome Evolution Protocol (GEP) for auditable, reusable evolution assets.

Ecosystem
npmjs.org
Latest Release
1.80.7
5 days ago
Versions
99
Downloads
14,087 last month
High
GSA_kwCzR0hTQS1qeGg4LWpoNzcteGg2Z84ABWNN
@evomap/evolver's validator sandbox allowlist permits `npm`/`npx`, yielding RCE from Hub-delivered validation tasks via lifecycle scripts
Ecosystems: npm
Packages: @evomap/evolver
Source: github
Published: 9 days ago
Moderate
GSA_kwCzR0hTQS03eHA3LW0zOTItaDkyY84ABWNM
@evomap/evolver has an unbounded request body in proxy /asset/submit that causes persistent disk-exhaustion DoS
Ecosystems: npm
Packages: @evomap/evolver
Source: github
Published: 9 days ago
High
GSA_kwCzR0hTQS1jZmNqLWhxcGYtaGNjZs4ABWNL
@evomap/evolver: Path Traversal in `evolver fetch` default-branch `safeId` allows Hub-controlled overwrite of project files (RCE)
Ecosystems: npm
Packages: @evomap/evolver
Source: github
Published: 9 days ago
High
GSA_kwCzR0hTQS1yNDY2LXJ4dzQtM2o5as4ABVqp
Evolver: Path Traversal via `--out` flag in `fetch` command allows Arbitrary File Write
Ecosystems: npm
Packages: @evomap/evolver
Source: github
Published: 22 days ago
Critical
GSA_kwCzR0hTQS1qNXc1LTU2OHgtcnE1M84ABVqo
Evolver: Command Injection via `execSync` in `_extractLLM()` function allows Remote Code Execution
Ecosystems: npm
Packages: @evomap/evolver
Source: github
Published: 22 days ago
Moderate
GSA_kwCzR0hTQS0yY2pyLTV2M2gtdjJ3NM4ABVqn
Evolver has Prototype Pollution via `Object.assign()` in its mailbox store operations
Ecosystems: npm
Packages: @evomap/evolver
Source: github
Published: 22 days ago
Links
Registry npmjs.org
Source Repository
Homepage Homepage
JSON API View JSON
CodeMeta codemeta.json
Repository
Stars 7,189 on GitHub
Forks 726 on GitHub