DEV Community

npm

Node Package Manager

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Spotify Verified for Human Artists: What It Signals for Code, Content, and My Own Blog

Spotify Verified for Human Artists: What It Signals for Code, Content, and My Own Blog

1
Comments
8 min read
Spotify Verified para artistas humanos: lo que esto anticipa para el código, el contenido y mi propio blog

Spotify Verified para artistas humanos: lo que esto anticipa para el código, el contenido y mi propio blog

Comments
9 min read
gni-compression is on npm — What a month of building a domain-adaptive LLM compressor taught me

gni-compression is on npm — What a month of building a domain-adaptive LLM compressor taught me

Comments
3 min read
Governing npm Dependencies Across a Monorepo

Governing npm Dependencies Across a Monorepo

4
Comments
11 min read
npm installs packages blindly — I built a CLI to fix that

npm installs packages blindly — I built a CLI to fix that

Comments
1 min read
Hono Has 34M Weekly Downloads and One Maintainer

Hono Has 34M Weekly Downloads and One Maintainer

Comments
3 min read
Four MCP packages, four ways the supply chain shifted in two weeks of npm monitoring

Four MCP packages, four ways the supply chain shifted in two weeks of npm monitoring

Comments
7 min read
You've probably never heard of these npm packages. They're in your production app.

You've probably never heard of these npm packages. They're in your production app.

Comments
3 min read
Hardening npm dependency security

Hardening npm dependency security

Comments
4 min read
Three npm Disasters That Were Predictable (And What the Signals Looked Like)

Three npm Disasters That Were Predictable (And What the Signals Looked Like)

1
Comments
6 min read
I audited 25 top npm packages with a zero-install CLI. Here's who passes.

I audited 25 top npm packages with a zero-install CLI. Here's who passes.

1
Comments
4 min read
The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.

The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.

1
Comments
4 min read
When GitHub Actions Goes Silent: The Pending-Forever Bug I Hit Shipping My MCP Server to npm

When GitHub Actions Goes Silent: The Pending-Forever Bug I Hit Shipping My MCP Server to npm

Comments
5 min read
AI Hallucinated Dependencies Are the New Supply Chain Attack: How to Stop Them

AI Hallucinated Dependencies Are the New Supply Chain Attack: How to Stop Them

Comments
8 min read
Publish your npm package using Changesets and GitHub actions

Publish your npm package using Changesets and GitHub actions

Comments
4 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.