DEV Community

npm

Node Package Manager

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Supply chain en npm vs PyPI: comparé mis dos simulaciones y el vector más peligroso no es el que todos creen

Supply chain en npm vs PyPI: comparé mis dos simulaciones y el vector más peligroso no es el que todos creen

Comments
10 min read
Supply chain npm vs PyPI: I compared both simulations and the most dangerous vector isn't what everyone thinks

Supply chain npm vs PyPI: I compared both simulations and the most dangerous vector isn't what everyone thinks

Comments
9 min read
Stop Shipping Broken Env Configs — I Built a Fix

Stop Shipping Broken Env Configs — I Built a Fix

Comments
2 min read
Why Your LLM Agent Forgot What It Did 5 Steps Ago

Why Your LLM Agent Forgot What It Did 5 Steps Ago

Comments
4 min read
Add Trust Scoring to Your CI Pipeline in 5 Minutes

Add Trust Scoring to Your CI Pipeline in 5 Minutes

Comments
3 min read
Add Real Business Trust Signals to Claude Desktop in 60 Seconds

Add Real Business Trust Signals to Claude Desktop in 60 Seconds

Comments
2 min read
AGENTS.md moved AI performance up a model tier. Package trust needs the same.

AGENTS.md moved AI performance up a model tier. Package trust needs the same.

Comments
2 min read
I never expected this response ~robot-toast

I never expected this response ~robot-toast

Comments
2 min read
npm audit no alcanza: simulé un supply chain attack sobre mis dependencias de Node y encontré lo que el scanner no ve

npm audit no alcanza: simulé un supply chain attack sobre mis dependencias de Node y encontré lo que el scanner no ve

Comments
10 min read
npm audit isn't enough: I simulated a supply chain attack on my Node dependencies and found what the scanner can't see

npm audit isn't enough: I simulated a supply chain attack on my Node dependencies and found what the scanner can't see

Comments
9 min read
Hardening Your npm CI in 5 Concrete Layers

Hardening Your npm CI in 5 Concrete Layers

Comments
2 min read
The NPM Audit Trap: A Thursday Morning Tragedy

The NPM Audit Trap: A Thursday Morning Tragedy

Comments
2 min read
Hi all

Hi all

Comments
1 min read
Modern JavaScript Tooling Explained: npm, npx, pnpm, Yarn & Bun

Modern JavaScript Tooling Explained: npm, npx, pnpm, Yarn & Bun

1
Comments
5 min read
"Why I stopped trusting npm audit (and built my own)"

"Why I stopped trusting npm audit (and built my own)"

Comments
3 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.