What happened
promptfoo (LLM red-teaming/eval OSS tool) released 0.122.0 on Aug 4, 2026, excluding compromised cache-manager/@cacheable/utils npm versions tied to the Shai-Hulud supply-chain attack, patching undici in code-scan-action, and dropping Node.js 20 support.
Why it matters
A widely used (500k+ weekly downloads) open-source LLM red-teaming/eval framework proactively hardened itself against an active npm supply-chain compromise, relevant to teams embedding promptfoo in CI pipelines for AI red-teaming.
Applicability
Teams using promptfoo for LLM security evaluation/red-teaming in CI should upgrade to 0.122.0+ and verify lockfiles are not pinned to compromised dependency versions.