Forem

npm

Node Package Manager

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
npm package commitment scores: zod has 139M weekly downloads and one maintainer

npm package commitment scores: zod has 139M weekly downloads and one maintainer

Comments
4 min read
I audited 10 common npm packages. Three came back CRITICAL. One was just attacked last week.

I audited 10 common npm packages. Three came back CRITICAL. One was just attacked last week.

Comments
3 min read
The Axios Attack Proved npm audit Is Broken. Here's What Would Have Caught It

The Axios Attack Proved npm audit Is Broken. Here's What Would Have Caught It

1
Comments
6 min read
The Documentation Attack Surface: How npm Libraries Teach Insecure Patterns

The Documentation Attack Surface: How npm Libraries Teach Insecure Patterns

Comments
4 min read
I built Material Symbols SVG, an icon library for using Material Symbols as SVG components
Cover image for I built Material Symbols SVG, an icon library for using Material Symbols as SVG components

I built Material Symbols SVG, an icon library for using Material Symbols as SVG components

Comments
5 min read
Why Your AI Coding Agent Keeps Recommending Dead Packages

Why Your AI Coding Agent Keeps Recommending Dead Packages

1
Comments
2 min read
I never expected this response ~robot-toast

I never expected this response ~robot-toast

Comments
2 min read
Malicious npm Packages Disguised as Strapi Plugins Enable Data Exfiltration and Remote Code Execution

Malicious npm Packages Disguised as Strapi Plugins Enable Data Exfiltration and Remote Code Execution

Comments
7 min read
Supply Chain Security measures
Cover image for Supply Chain Security measures

Supply Chain Security measures

Comments
1 min read
Shipping a Go CLI to Every Ecosystem: GitHub Releases, Homebrew, and npm
Cover image for Shipping a Go CLI to Every Ecosystem: GitHub Releases, Homebrew, and npm

Shipping a Go CLI to Every Ecosystem: GitHub Releases, Homebrew, and npm

Comments
5 min read
npm audit isn't enough: I simulated a supply chain attack on my Node dependencies and found what the scanner can't see
Cover image for npm audit isn't enough: I simulated a supply chain attack on my Node dependencies and found what the scanner can't see

npm audit isn't enough: I simulated a supply chain attack on my Node dependencies and found what the scanner can't see

1
Comments
9 min read
npm audit no alcanza: simulé un supply chain attack sobre mis dependencias de Node y encontré lo que el scanner no ve
Cover image for npm audit no alcanza: simulé un supply chain attack sobre mis dependencias de Node y encontré lo que el scanner no ve

npm audit no alcanza: simulé un supply chain attack sobre mis dependencias de Node y encontré lo que el scanner no ve

1
Comments
10 min read
The Axios/npm Incident & Why AI Won’t Replace Devs

The Axios/npm Incident & Why AI Won’t Replace Devs

Comments
1 min read
I built an npm malware scanner and found 21 malicious packages in 24 hours

I built an npm malware scanner and found 21 malicious packages in 24 hours

Comments 1
1 min read
How the axios@1.14.1 supply chain attack worked (and how to protect yourself)

How the axios@1.14.1 supply chain attack worked (and how to protect yourself)

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.