DEV Community

npm

Node Package Manager

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
42 @tanstack/* Packages Were Compromised on npm: What Happened, How It Works, and What You Must Do Right Now

42 @tanstack/* Packages Were Compromised on npm: What Happened, How It Works, and What You Must Do Right Now

Comments
10 min read
The TanStack npm Attack Shows Why pnpm 11 Matters

The TanStack npm Attack Shows Why pnpm 11 Matters

2
Comments
3 min read
LibKill: Scan Your Machine for Compromised npm, pip, and Bun Packages

LibKill: Scan Your Machine for Compromised npm, pip, and Bun Packages

Comments
3 min read
Mini Shai-Hulud: A persistent supply-chain worm

Mini Shai-Hulud: A persistent supply-chain worm

1
Comments 1
3 min read
The Worm in the Registry

The Worm in the Registry

2
Comments
10 min read
Docker Caching Strategies That Actually Work with npm ci

Docker Caching Strategies That Actually Work with npm ci

Comments
2 min read
Deep Dive: TanStack npm supply-chain compromise

Deep Dive: TanStack npm supply-chain compromise

1
Comments
3 min read
Building a CLI Tool with Node.js (From Zero to npm)

Building a CLI Tool with Node.js (From Zero to npm)

Comments
4 min read
I Built My Own Config Format for Node.js That Separates Server and Client Secrets

I Built My Own Config Format for Node.js That Separates Server and Client Secrets

1
Comments 2
5 min read
Scanning npm Packages for Malware Before You Install, Without Running Them

Scanning npm Packages for Malware Before You Install, Without Running Them

Comments 2
6 min read
Supply chain en npm vs PyPI: comparé mis dos simulaciones y el vector más peligroso no es el que todos creen

Supply chain en npm vs PyPI: comparé mis dos simulaciones y el vector más peligroso no es el que todos creen

Comments
10 min read
Supply chain npm vs PyPI: I compared both simulations and the most dangerous vector isn't what everyone thinks

Supply chain npm vs PyPI: I compared both simulations and the most dangerous vector isn't what everyone thinks

Comments
9 min read
Stop Shipping Broken Env Configs — I Built a Fix

Stop Shipping Broken Env Configs — I Built a Fix

Comments
2 min read
Why I Stopped Writing 15 * 60 * 1000 in Every Project

Why I Stopped Writing 15 * 60 * 1000 in Every Project

3
Comments 5
5 min read
AGENTS.md moved AI performance up a model tier. Package trust needs the same.

AGENTS.md moved AI performance up a model tier. Package trust needs the same.

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.