Forem

npm

Node Package Manager

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Axios Compromise: What Actually Happened

Axios Compromise: What Actually Happened

Comments
4 min read
Malicious axios Update Exploits Dependency Trust Model

Malicious axios Update Exploits Dependency Trust Model

Comments
3 min read
The Hidden Cost of AI Coding Agents: Every Tool Is Fetching the Same Data

The Hidden Cost of AI Coding Agents: Every Tool Is Fetching the Same Data

Comments
6 min read
I built Inklin because I wanted a better terminal styling experience for Node.js

I built Inklin because I wanted a better terminal styling experience for Node.js

2
Comments
2 min read
Bun replaced 4 tools in my stack — here's what actually held up and what didn't
Cover image for Bun replaced 4 tools in my stack — here's what actually held up and what didn't

Bun replaced 4 tools in my stack — here's what actually held up and what didn't

Comments
2 min read
Did Your Fix Actually Work? Comparing Profiling Reports Before and After

Did Your Fix Actually Work? Comparing Profiling Reports Before and After

1
Comments
4 min read
How Commit Scores npm Packages: The Methodology Behind getcommit.dev/audit

How Commit Scores npm Packages: The Methodology Behind getcommit.dev/audit

Comments
9 min read
MCPwn Is Live. We Scanned the Supply Chains of 14 MCP Servers.

MCPwn Is Live. We Scanned the Supply Chains of 14 MCP Servers.

Comments 2
5 min read
I audited every npm package with >10M weekly downloads. Here is the risk map.

I audited every npm package with >10M weekly downloads. Here is the risk map.

Comments
4 min read
Your package.json only shows 20 dependencies. Your lock file has 487. I built a scanner for the other 467.

Your package.json only shows 20 dependencies. Your lock file has 487. I built a scanner for the other 467.

Comments
2 min read
esbuild has 190M weekly downloads and one maintainer — I audited 25 top npm packages

esbuild has 190M weekly downloads and one maintainer — I audited 25 top npm packages

Comments
3 min read
I stopped waiting for backend APIs - localmockdb made frontend development easier
Cover image for I stopped waiting for backend APIs - localmockdb made frontend development easier

I stopped waiting for backend APIs - localmockdb made frontend development easier

Comments
4 min read
I audited 25 top npm packages with a zero-install CLI. Here's who passes.

I audited 25 top npm packages with a zero-install CLI. Here's who passes.

Comments
3 min read
thusdev-fetch atteint 256 téléchargements npm en 2 jours !

thusdev-fetch atteint 256 téléchargements npm en 2 jours !

3
Comments
1 min read
My AI told me to pip install a package that doesn't exist. Turns out someone already weaponized that.

My AI told me to pip install a package that doesn't exist. Turns out someone already weaponized that.

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.