Forem

npm

Node Package Manager

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
LibKill: Scan Your Machine for Compromised npm, pip, and Bun Packages
Cover image for LibKill: Scan Your Machine for Compromised npm, pip, and Bun Packages

LibKill: Scan Your Machine for Compromised npm, pip, and Bun Packages

Comments
3 min read
The Worm in the Registry
Cover image for The Worm in the Registry

The Worm in the Registry

2
Comments
10 min read
Deep Dive: TanStack npm supply-chain compromise
Cover image for Deep Dive: TanStack npm supply-chain compromise

Deep Dive: TanStack npm supply-chain compromise

1
Comments
3 min read
Building a CLI Tool with Node.js (From Zero to npm)

Building a CLI Tool with Node.js (From Zero to npm)

Comments
4 min read
I Built My Own Config Format for Node.js That Separates Server and Client Secrets

I Built My Own Config Format for Node.js That Separates Server and Client Secrets

1
Comments 2
5 min read
Supply chain en npm vs PyPI: comparé mis dos simulaciones y el vector más peligroso no es el que todos creen
Cover image for Supply chain en npm vs PyPI: comparé mis dos simulaciones y el vector más peligroso no es el que todos creen

Supply chain en npm vs PyPI: comparé mis dos simulaciones y el vector más peligroso no es el que todos creen

Comments
10 min read
Supply chain npm vs PyPI: I compared both simulations and the most dangerous vector isn't what everyone thinks
Cover image for Supply chain npm vs PyPI: I compared both simulations and the most dangerous vector isn't what everyone thinks

Supply chain npm vs PyPI: I compared both simulations and the most dangerous vector isn't what everyone thinks

Comments
9 min read
Stop Shipping Broken Env Configs — I Built a Fix

Stop Shipping Broken Env Configs — I Built a Fix

Comments
2 min read
Why I Stopped Writing 15 * 60 * 1000 in Every Project
Cover image for Why I Stopped Writing 15 * 60 * 1000 in Every Project

Why I Stopped Writing 15 * 60 * 1000 in Every Project

3
Comments 5
5 min read
Add Trust Scoring to Your CI Pipeline in 5 Minutes

Add Trust Scoring to Your CI Pipeline in 5 Minutes

Comments
3 min read
Add Real Business Trust Signals to Claude Desktop in 60 Seconds

Add Real Business Trust Signals to Claude Desktop in 60 Seconds

Comments
2 min read
AGENTS.md moved AI performance up a model tier. Package trust needs the same.

AGENTS.md moved AI performance up a model tier. Package trust needs the same.

Comments
2 min read
Mini Shai-Hulud: un gusano de cadena de suministro que explotó TanStack y el ecosistema npm.
Cover image for Mini Shai-Hulud: un gusano de cadena de suministro que explotó TanStack y el ecosistema npm.

Mini Shai-Hulud: un gusano de cadena de suministro que explotó TanStack y el ecosistema npm.

2
Comments
5 min read
Why you keep attacking npm?

Why you keep attacking npm?

2
Comments
1 min read
The NPM Audit Trap: A Thursday Morning Tragedy

The NPM Audit Trap: A Thursday Morning Tragedy

Comments
2 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.