Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
npm
Follow
Hide
Node Package Manager
Posts
Left menu
👋
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
I audited every npm package with >10M weekly downloads. Here is the risk map.
Pico
Pico
Pico
Follow
Apr 17
I audited every npm package with >10M weekly downloads. Here is the risk map.
#
security
#
npm
#
javascript
#
devops
Comments
Add Comment
4 min read
esbuild has 190M weekly downloads and one maintainer — I audited 25 top npm packages
Pico
Pico
Pico
Follow
Apr 17
esbuild has 190M weekly downloads and one maintainer — I audited 25 top npm packages
#
npm
#
security
#
javascript
#
devops
Comments
Add Comment
3 min read
Launching gh-dep-risk: a GitHub CLI extension for npm dependency PR review
Monde kim
Monde kim
Monde kim
Follow
Apr 16
Launching gh-dep-risk: a GitHub CLI extension for npm dependency PR review
#
github
#
cli
#
security
#
npm
Comments
Add Comment
1 min read
thusdev-fetch atteint 256 téléchargements npm en 2 jours !
Malthus AMETEPE
Malthus AMETEPE
Malthus AMETEPE
Follow
Apr 16
thusdev-fetch atteint 256 téléchargements npm en 2 jours !
#
node
#
javascript
#
opensource
#
npm
3
reactions
Comments
Add Comment
1 min read
My AI told me to pip install a package that doesn't exist. Turns out someone already weaponized that.
Xihe 曦和
Xihe 曦和
Xihe 曦和
Follow
Apr 14
My AI told me to pip install a package that doesn't exist. Turns out someone already weaponized that.
#
ai
#
npm
#
security
#
testing
Comments
Add Comment
2 min read
Le migliori librerie di notifiche per React Native nel 2026: quale scegliere?
Marco Crupi
Marco Crupi
Marco Crupi
Follow
Apr 14
Le migliori librerie di notifiche per React Native nel 2026: quale scegliere?
#
reactnative
#
react
#
opensource
#
npm
Comments
Add Comment
7 min read
npm audit --json Is Unreadable. I Wrote a Formatter With Zero Dependencies.
SEN LLC
SEN LLC
SEN LLC
Follow
Apr 15
npm audit --json Is Unreadable. I Wrote a Formatter With Zero Dependencies.
#
typescript
#
npm
#
security
#
tutorial
2
reactions
Comments
Add Comment
8 min read
axios npm Supply Chain Attack (March 31, 2026) — What Happened and How to Check Your Lock File Right Now
LazyDev_OH
LazyDev_OH
LazyDev_OH
Follow
Apr 14
axios npm Supply Chain Attack (March 31, 2026) — What Happened and How to Check Your Lock File Right Now
#
security
#
npm
#
javascript
#
webdev
1
reaction
Comments
Add Comment
6 min read
All It Took Was npm install (Axios Attack)
Chioma Halim
Chioma Halim
Chioma Halim
Follow
Apr 13
All It Took Was npm install (Axios Attack)
#
npm
#
webdev
#
cybersecurity
#
node
1
reaction
Comments
Add Comment
4 min read
Completing the Picture: Adding Memory Diagnostics to a CPU Profiler
Bill Tu
Bill Tu
Bill Tu
Follow
Apr 13
Completing the Picture: Adding Memory Diagnostics to a CPU Profiler
#
npm
#
node
#
javascript
Comments
Add Comment
6 min read
Signals, Effects, and the Algebra Between Them
Ja
Ja
Ja
Follow
Apr 13
Signals, Effects, and the Algebra Between Them
#
typescript
#
npm
#
datastructures
#
node
Comments
Add Comment
6 min read
I audited the top 50 npm packages. Almost none ship with supply-chain attestations!
The Crypto Donkey
The Crypto Donkey
The Crypto Donkey
Follow
Apr 13
I audited the top 50 npm packages. Almost none ship with supply-chain attestations!
#
webdev
#
javascript
#
security
#
npm
Comments
Add Comment
10 min read
I just hardened my OSS release pipeline to 11 layers of security — here's the playbook
אחיה כהן
אחיה כהן
אחיה כהן
Follow
Apr 11
I just hardened my OSS release pipeline to 11 layers of security — here's the playbook
#
opensource
#
security
#
github
#
npm
Comments
Add Comment
7 min read
Rust Binary Distribution via npm: Addressing Security Risks and Installation Failures with Native Caching Solutions
Pavel Kostromin
Pavel Kostromin
Pavel Kostromin
Follow
Apr 11
Rust Binary Distribution via npm: Addressing Security Risks and Installation Failures with Native Caching Solutions
#
rust
#
npm
#
security
#
distribution
Comments
Add Comment
12 min read
I published mfkvault-cli to npm — install any AI skill in 30 seconds
Faiyaz Khan
Faiyaz Khan
Faiyaz Khan
Follow
Apr 11
I published mfkvault-cli to npm — install any AI skill in 30 seconds
#
claude
#
ai
#
npm
#
productivity
Comments
Add Comment
1 min read
👋
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account