Forem

npm

Node Package Manager

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Le migliori librerie di notifiche per React Native nel 2026: quale scegliere?
Cover image for Le migliori librerie di notifiche per React Native nel 2026: quale scegliere?

Le migliori librerie di notifiche per React Native nel 2026: quale scegliere?

Comments
7 min read
axios npm Supply Chain Attack (March 31, 2026) — What Happened and How to Check Your Lock File Right Now
Cover image for axios npm Supply Chain Attack (March 31, 2026) — What Happened and How to Check Your Lock File Right Now

axios npm Supply Chain Attack (March 31, 2026) — What Happened and How to Check Your Lock File Right Now

1
Comments
6 min read
axios Was Attacked. npm audit Showed Zero Issues. Here's What Behavioral Scoring Showed.

axios Was Attacked. npm audit Showed Zero Issues. Here's What Behavioral Scoring Showed.

Comments
4 min read
All It Took Was npm install (Axios Attack)
Cover image for All It Took Was npm install (Axios Attack)

All It Took Was npm install (Axios Attack)

1
Comments
4 min read
Completing the Picture: Adding Memory Diagnostics to a CPU Profiler

Completing the Picture: Adding Memory Diagnostics to a CPU Profiler

Comments
6 min read
Signals, Effects, and the Algebra Between Them
Cover image for Signals, Effects, and the Algebra Between Them

Signals, Effects, and the Algebra Between Them

Comments
6 min read
I audited the top 50 npm packages. Almost none ship with supply-chain attestations!
Cover image for I audited the top 50 npm packages. Almost none ship with supply-chain attestations!

I audited the top 50 npm packages. Almost none ship with supply-chain attestations!

Comments
10 min read
The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.

The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.

Comments
4 min read
The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Aren't.

The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Aren't.

Comments
3 min read
I just hardened my OSS release pipeline to 11 layers of security — here's the playbook
Cover image for I just hardened my OSS release pipeline to 11 layers of security — here's the playbook

I just hardened my OSS release pipeline to 11 layers of security — here's the playbook

Comments
7 min read
You can now explore npm dependency trees visually — see transitive CRITICAL risks in seconds

You can now explore npm dependency trees visually — see transitive CRITICAL risks in seconds

Comments
2 min read
Announcing markdown-parser-react v3.0.0: A Complete Architectural Overhaul
Cover image for Announcing markdown-parser-react v3.0.0: A Complete Architectural Overhaul

Announcing markdown-parser-react v3.0.0: A Complete Architectural Overhaul

Comments
3 min read
Rust Binary Distribution via npm: Addressing Security Risks and Installation Failures with Native Caching Solutions

Rust Binary Distribution via npm: Addressing Security Risks and Installation Failures with Native Caching Solutions

Comments
12 min read
I published mfkvault-cli to npm — install any AI skill in 30 seconds

I published mfkvault-cli to npm — install any AI skill in 30 seconds

Comments
1 min read
How to Create Multi-Page TIFF Files in Node.js (Without ImageMagick)

How to Create Multi-Page TIFF Files in Node.js (Without ImageMagick)

Comments
2 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.