Forem

npm

Node Package Manager

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Hi all

Hi all

Comments
1 min read
Modern JavaScript Tooling Explained: npm, npx, pnpm, Yarn & Bun
Cover image for Modern JavaScript Tooling Explained: npm, npx, pnpm, Yarn & Bun

Modern JavaScript Tooling Explained: npm, npx, pnpm, Yarn & Bun

1
Comments
5 min read
"Why I stopped trusting npm audit (and built my own)"

"Why I stopped trusting npm audit (and built my own)"

Comments
3 min read
Your package.json only shows 20 dependencies. Your lock file has 487. I built a scanner for the other 467.

Your package.json only shows 20 dependencies. Your lock file has 487. I built a scanner for the other 467.

Comments
2 min read
I Added OpenSSF Scorecard to getcommit.dev. The Results Tell Two Different Stories.

I Added OpenSSF Scorecard to getcommit.dev. The Results Tell Two Different Stories.

Comments
3 min read
Why npm supply chain attacks keep happening and how to harden your installs
Cover image for Why npm supply chain attacks keep happening and how to harden your installs

Why npm supply chain attacks keep happening and how to harden your installs

Comments
4 min read
guard-install now scans GitHub repos before you run them

guard-install now scans GitHub repos before you run them

Comments
1 min read
Two Independent Attack Surfaces: Why npm Provenance Doesn't Make a Package Safe

Two Independent Attack Surfaces: Why npm Provenance Doesn't Make a Package Safe

Comments
3 min read
Two Types of npm Supply Chain Attack: What Catches Each

Two Types of npm Supply Chain Attack: What Catches Each

Comments
5 min read
Proof-of-Commitment Internals: How the Scoring Algorithm Works

Proof-of-Commitment Internals: How the Scoring Algorithm Works

1
Comments
6 min read
Spotify Verified for Human Artists: What It Signals for Code, Content, and My Own Blog
Cover image for Spotify Verified for Human Artists: What It Signals for Code, Content, and My Own Blog

Spotify Verified for Human Artists: What It Signals for Code, Content, and My Own Blog

1
Comments
8 min read
certifi has 350M weekly downloads and one publisher. It handles your SSL certificates.

certifi has 350M weekly downloads and one publisher. It handles your SSL certificates.

Comments
4 min read
From pnpm's Cool Feature to npm's Life jacket: The (somewhat accidental) birth of age-install

From pnpm's Cool Feature to npm's Life jacket: The (somewhat accidental) birth of age-install

Comments
6 min read
npm installs packages blindly — I built a CLI to fix that

npm installs packages blindly — I built a CLI to fix that

Comments
1 min read
Hono Has 34M Weekly Downloads and One Maintainer

Hono Has 34M Weekly Downloads and One Maintainer

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.