DEV Community

npm

Node Package Manager

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
guard-install now scans GitHub repos before you run them

guard-install now scans GitHub repos before you run them

Comments
1 min read
Proof-of-Commitment Internals: How the Scoring Algorithm Works

Proof-of-Commitment Internals: How the Scoring Algorithm Works

1
Comments
6 min read
Spotify Verified for Human Artists: What It Signals for Code, Content, and My Own Blog

Spotify Verified for Human Artists: What It Signals for Code, Content, and My Own Blog

1
Comments
8 min read
hashfree: Clean URL Section Navigation Without the #

hashfree: Clean URL Section Navigation Without the #

4
Comments
2 min read
npm installs packages blindly — I built a CLI to fix that

npm installs packages blindly — I built a CLI to fix that

Comments
1 min read
Hono Has 34M Weekly Downloads and One Maintainer

Hono Has 34M Weekly Downloads and One Maintainer

Comments
3 min read
Four MCP packages, four ways the supply chain shifted in two weeks of npm monitoring

Four MCP packages, four ways the supply chain shifted in two weeks of npm monitoring

Comments
7 min read
You've probably never heard of these npm packages. They're in your production app.

You've probably never heard of these npm packages. They're in your production app.

Comments
3 min read
Hardening npm dependency security

Hardening npm dependency security

Comments
4 min read
Three npm Disasters That Were Predictable (And What the Signals Looked Like)

Three npm Disasters That Were Predictable (And What the Signals Looked Like)

1
Comments
6 min read
I audited 25 top npm packages with a zero-install CLI. Here's who passes.

I audited 25 top npm packages with a zero-install CLI. Here's who passes.

1
Comments
4 min read
When GitHub Actions Goes Silent: The Pending-Forever Bug I Hit Shipping My MCP Server to npm

When GitHub Actions Goes Silent: The Pending-Forever Bug I Hit Shipping My MCP Server to npm

Comments
5 min read
AI Hallucinated Dependencies Are the New Supply Chain Attack: How to Stop Them

AI Hallucinated Dependencies Are the New Supply Chain Attack: How to Stop Them

Comments
8 min read
Publish your npm package using Changesets and GitHub actions

Publish your npm package using Changesets and GitHub actions

Comments
4 min read
How to Automate OTP Extraction and Email Testing in n8n with Disposable Inboxes

How to Automate OTP Extraction and Email Testing in n8n with Disposable Inboxes

Comments
3 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.