Forem

npm

Node Package Manager

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Four MCP packages, four ways the supply chain shifted in two weeks of npm monitoring

Four MCP packages, four ways the supply chain shifted in two weeks of npm monitoring

Comments
7 min read
You've probably never heard of these npm packages. They're in your production app.

You've probably never heard of these npm packages. They're in your production app.

Comments
3 min read
How npm Behavioral Risk Scoring Works: The Methodology Behind getcommit.dev

How npm Behavioral Risk Scoring Works: The Methodology Behind getcommit.dev

Comments
9 min read
The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.

The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.

Comments
4 min read
Hardening npm dependency security

Hardening npm dependency security

Comments
4 min read
Hono Has 35M Weekly Downloads and One npm Publisher

Hono Has 35M Weekly Downloads and One npm Publisher

Comments
3 min read
Three npm Disasters That Were Predictable (And What the Signals Looked Like)

Three npm Disasters That Were Predictable (And What the Signals Looked Like)

1
Comments
6 min read
npm audit, Socket, Snyk, and Commit: An Honest Comparison

npm audit, Socket, Snyk, and Commit: An Honest Comparison

Comments
5 min read
I audited 25 top npm packages with a zero-install CLI. Here's who passes.

I audited 25 top npm packages with a zero-install CLI. Here's who passes.

1
Comments
4 min read
I Built a 8.7KB React Animation Library (120+ FPS) on top of GSAP
Cover image for I Built a 8.7KB React Animation Library (120+ FPS) on top of GSAP

I Built a 8.7KB React Animation Library (120+ FPS) on top of GSAP

3
Comments
1 min read
AI Hallucinated Dependencies Are the New Supply Chain Attack: How to Stop Them

AI Hallucinated Dependencies Are the New Supply Chain Attack: How to Stop Them

Comments
8 min read
When GitHub Actions Goes Silent: The Pending-Forever Bug I Hit Shipping My MCP Server to npm

When GitHub Actions Goes Silent: The Pending-Forever Bug I Hit Shipping My MCP Server to npm

Comments
5 min read
`npm fund`

`npm fund`

1
Comments
1 min read
How to Automate OTP Extraction and Email Testing in n8n with Disposable Inboxes
Cover image for How to Automate OTP Extraction and Email Testing in n8n with Disposable Inboxes

How to Automate OTP Extraction and Email Testing in n8n with Disposable Inboxes

Comments
3 min read
The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Are Not.

The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Are Not.

Comments
3 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.