Forem

npm

Node Package Manager

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Setting GitHub as a trusted publisher for npm
Cover image for Setting GitHub as a trusted publisher for npm

Setting GitHub as a trusted publisher for npm

1
Comments
2 min read
Malicious `axios@1.14.1` Published: Exfiltrated CI/CD Secrets; Pin Dependency Versions to Mitigate

Malicious `axios@1.14.1` Published: Exfiltrated CI/CD Secrets; Pin Dependency Versions to Mitigate

Comments
12 min read
npm Publish Without Tokens

npm Publish Without Tokens

Comments
3 min read
Debugging Node.js in Docker and Kubernetes Without Restarting

Debugging Node.js in Docker and Kubernetes Without Restarting

Comments
6 min read
Building a Reusable React Knowledge Graph Component: OKVE v0.3.0

Building a Reusable React Knowledge Graph Component: OKVE v0.3.0

Comments
1 min read
7 Bugs That Taught Us How to Build Better Diagnostic Tools

7 Bugs That Taught Us How to Build Better Diagnostic Tools

1
Comments
8 min read
Beyond the Event Loop: Tracking Slow I/O in Production Node.js

Beyond the Event Loop: Tracking Slow I/O in Production Node.js

Comments
8 min read
Validando CNPJ de forma definitiva: Conheça a cnpj-universal (JS/TS)

Validando CNPJ de forma definitiva: Conheça a cnpj-universal (JS/TS)

Comments
2 min read
The Axios Supply Chain Attack Explained — npm's Biggest Security Breach in 2026

The Axios Supply Chain Attack Explained — npm's Biggest Security Breach in 2026

Comments
16 min read
20 one-shot prompts that turn Kanban into an autonomous coding machine
Cover image for 20 one-shot prompts that turn Kanban into an autonomous coding machine

20 one-shot prompts that turn Kanban into an autonomous coding machine

1
Comments
11 min read
Paste your package.json, see which dependencies are CRITICAL supply chain risks

Paste your package.json, see which dependencies are CRITICAL supply chain risks

Comments
2 min read
Axios Was Compromised. Here's What It Means for Your Repo.
Cover image for Axios Was Compromised. Here's What It Means for Your Repo.

Axios Was Compromised. Here's What It Means for Your Repo.

Comments
3 min read
npm package commitment scores: zod has 139M weekly downloads and one maintainer

npm package commitment scores: zod has 139M weekly downloads and one maintainer

Comments
4 min read
I audited 10 common npm packages. Three came back CRITICAL. One was just attacked last week.

I audited 10 common npm packages. Three came back CRITICAL. One was just attacked last week.

Comments
3 min read
The Axios Attack Proved npm audit Is Broken. Here's What Would Have Caught It

The Axios Attack Proved npm audit Is Broken. Here's What Would Have Caught It

1
Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.