<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: nepeckman</title>
    <description>The latest articles on DEV Community by nepeckman (@nepeckman).</description>
    <link>https://dev.to/nepeckman</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3067%2F11321895.png</url>
      <title>DEV Community: nepeckman</title>
      <link>https://dev.to/nepeckman</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/nepeckman"/>
    <language>en</language>
    <item>
      <title>Have you ever lost your job?</title>
      <dc:creator>nepeckman</dc:creator>
      <pubDate>Mon, 22 Jul 2019 16:54:25 +0000</pubDate>
      <link>https://dev.to/nepeckman/have-you-ever-lost-your-job-5eh0</link>
      <guid>https://dev.to/nepeckman/have-you-ever-lost-your-job-5eh0</guid>
      <description>&lt;p&gt;I was recently laid off as my division was downsized. It was about as amicable as the situation could be, I left on good terms with my manager and have plenty of positive references. But I can't help feeling a little depressed. Who else here has ever lost their job? What was the experience like? How long did it take you to move past it? How was the following job search?&lt;/p&gt;

</description>
      <category>discuss</category>
      <category>watercooler</category>
    </item>
    <item>
      <title>How do we improve security in the npm ecosystem?</title>
      <dc:creator>nepeckman</dc:creator>
      <pubDate>Mon, 26 Nov 2018 18:02:28 +0000</pubDate>
      <link>https://dev.to/nepeckman/how-do-we-improve-security-in-the-npm-ecosystem-3hmj</link>
      <guid>https://dev.to/nepeckman/how-do-we-improve-security-in-the-npm-ecosystem-3hmj</guid>
      <description>&lt;p&gt;For those who haven't seen this trending elsewhere, &lt;a href="https://github.com/dominictarr/event-stream/issues/116" rel="noopener noreferrer"&gt;a popular npm library executed malicious code on victims' computers&lt;/a&gt;. To summarize the thread (though it is worth a read) the maintainer of the library gave control to an unknown individual who claimed they wanted to maintain it. This individual added a dependency designed to execute some sort of malicious code, and people are still trying to figure out what the payload does. While a lot of people are playing the blame game, I'm interested in discussing what practical steps can be taken to limit this vector of attack. Should we establish a more rigorous process for giving up control of an npm module? Is our only hope better audit tools? I'm interested in any idea that addresses this security concern.&lt;/p&gt;

</description>
      <category>security</category>
      <category>javascript</category>
      <category>npm</category>
      <category>discuss</category>
    </item>
  </channel>
</rss>
