DEV Community

npm

Node Package Manager

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Khmer Hybrid Calendar v1.1.0 Released — Complete Holidays, UNESCO Heritage & 10x Faster 🚀

Khmer Hybrid Calendar v1.1.0 Released — Complete Holidays, UNESCO Heritage & 10x Faster 🚀

Comments
2 min read
Mitigating Security Risks from Malicious npm Packages Through Enhanced Vetting and Monitoring

Mitigating Security Risks from Malicious npm Packages Through Enhanced Vetting and Monitoring

Comments
13 min read
We Blamed the Market for a Metric Our Own Clients Broke

We Blamed the Market for a Metric Our Own Clients Broke

Comments
6 min read
yarn.lock: may the `--force` be with you

yarn.lock: may the `--force` be with you

1
Comments 1
14 min read
yarn.lock: you can't `sed` a graph

yarn.lock: you can't `sed` a graph

1
Comments 1
10 min read
CaptchaKit: A Self-Hosted CAPTCHA Package for React & Next.js + Try It Live

CaptchaKit: A Self-Hosted CAPTCHA Package for React & Next.js + Try It Live

5
Comments
1 min read
express-validator

express-validator

1
Comments
6 min read
None of the Big Package Registries Can Tell You If a Dependency Is Abandoned

None of the Big Package Registries Can Tell You If a Dependency Is Abandoned

Comments 2
7 min read
AI Coding Assistants Invent Fake Packages 1 in 5 Times — Attackers Are Already Registering Them

AI Coding Assistants Invent Fake Packages 1 in 5 Times — Attackers Are Already Registering Them

Comments
2 min read
Modern Open-Source Maintenance: Secure Package Publishing, SemVer, and Automated Scanning

Modern Open-Source Maintenance: Secure Package Publishing, SemVer, and Automated Scanning

Comments
9 min read
Your npm install Is Doing More Than You Think

Your npm install Is Doing More Than You Think

1
Comments 2
7 min read
A Supply-Chain Attack Hit Our Repos. Here's How We Locked Down GitHub So It Can't Happen Again

A Supply-Chain Attack Hit Our Repos. Here's How We Locked Down GitHub So It Can't Happen Again

Comments
3 min read
capsurface: reviewing capability changes in npm dependencies

capsurface: reviewing capability changes in npm dependencies

1
Comments
5 min read
Left-pad incident explained: how 11 lines of JavaScript broke npm

Left-pad incident explained: how 11 lines of JavaScript broke npm

5
Picked as gem Comments
8 min read
The Shai-Hulud npm worm showed that opening a folder is enough to run code

The Shai-Hulud npm worm showed that opening a folder is enough to run code

Comments
3 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.