Solutions  ·  2026-08-11

promptfoo 0.122.0 patches supply-chain risk from Shai-Hulud npm compromise

SolutionsLow impactGlobal
promptfoo (LLM red-teaming/eval OSS tool) released 0.122.0 on Aug 4, 2026, excluding compromised cache-manager/@cacheable/utils npm versions tied to the Shai-Hulud supply-chain attack, patching undici in code-scan-action, and dropping Node.js 20 support.
A widely used (500k+ weekly downloads) open-source LLM red-teaming/eval framework proactively hardened itself against an active npm supply-chain compromise, relevant to teams embedding promptfoo in CI pipelines for AI red-teaming.
Teams using promptfoo for LLM security evaluation/red-teaming in CI should upgrade to 0.122.0+ and verify lockfiles are not pinned to compromised dependency versions.
GitHub promptfoo releases
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →