DEV Community

npm

Node Package Manager

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Supply Chain Attacks Aren't Just a Big Library Problem — Here's What You Can Do Today

Supply Chain Attacks Aren't Just a Big Library Problem — Here's What You Can Do Today

1
Comments
5 min read
npm Is on Fire: Why the Architecture Is the Product

npm Is on Fire: Why the Architecture Is the Product

Comments
10 min read
attw script in CopilotKit codebase.

attw script in CopilotKit codebase.

Comments
3 min read
PackVault: Cache npm Packages Once. Install Forever — Even Offline.

PackVault: Cache npm Packages Once. Install Forever — Even Offline.

5
Comments
2 min read
From Frustration to Automation

From Frustration to Automation

Comments
4 min read
Desenvolvendo aplicações web com Node.js: do primeiro servidor ao seu próprio roteador de URLs

Desenvolvendo aplicações web com Node.js: do primeiro servidor ao seu próprio roteador de URLs

1
Comments
13 min read
Scarab Diagnostic Field Test #024B — pnpm Accepted the CAFS TMPDIR Socket Budget Repair

Scarab Diagnostic Field Test #024B — pnpm Accepted the CAFS TMPDIR Socket Budget Repair

2
Comments
6 min read
The TanStack npm Attack Shows Why pnpm 11 Matters

The TanStack npm Attack Shows Why pnpm 11 Matters

2
Comments
3 min read
LibKill: Scan Your Machine for Compromised npm, pip, and Bun Packages

LibKill: Scan Your Machine for Compromised npm, pip, and Bun Packages

Comments
3 min read
Mini Shai-Hulud: A persistent supply-chain worm

Mini Shai-Hulud: A persistent supply-chain worm

1
Comments 1
3 min read
How I Built the Two Missing Payload CMS v3 Plugins — Reviews, JSON-LD & Real Production Bugs

How I Built the Two Missing Payload CMS v3 Plugins — Reviews, JSON-LD & Real Production Bugs

1
Comments
5 min read
52,000 packages passed every security check. Chainguard blocked them anyway.

52,000 packages passed every security check. Chainguard blocked them anyway.

Comments
3 min read
A CVE just hit your base image. Your scanner won't tell you which repos to fix.

A CVE just hit your base image. Your scanner won't tell you which repos to fix.

Comments
11 min read
Deep Dive: TanStack npm supply-chain compromise

Deep Dive: TanStack npm supply-chain compromise

1
Comments
3 min read
Building a CLI Tool with Node.js (From Zero to npm)

Building a CLI Tool with Node.js (From Zero to npm)

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.