DEV Community

npm

Node Package Manager

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
I Published My First npm Package — Here's Everything I Wish I Knew

I Published My First npm Package — Here's Everything I Wish I Knew

Comments
4 min read
Attempt to stop npm postinstall scripts from stealing your secrets

Attempt to stop npm postinstall scripts from stealing your secrets

1
Comments
4 min read
Supply Chain Attacks Aren't Just a Big Library Problem — Here's What You Can Do Today

Supply Chain Attacks Aren't Just a Big Library Problem — Here's What You Can Do Today

1
Comments
5 min read
npm Is on Fire: Why the Architecture Is the Product

npm Is on Fire: Why the Architecture Is the Product

Comments
10 min read
attw script in CopilotKit codebase.

attw script in CopilotKit codebase.

Comments
3 min read
From Frustration to Automation

From Frustration to Automation

Comments
4 min read
Desenvolvendo aplicações web com Node.js: do primeiro servidor ao seu próprio roteador de URLs

Desenvolvendo aplicações web com Node.js: do primeiro servidor ao seu próprio roteador de URLs

1
Comments
13 min read
`skills-npm`: a Stable Way to Distribute and Maintain Agent Skills

`skills-npm`: a Stable Way to Distribute and Maintain Agent Skills

Comments
3 min read
42 @tanstack/* Packages Were Compromised on npm: What Happened, How It Works, and What You Must Do Right Now

42 @tanstack/* Packages Were Compromised on npm: What Happened, How It Works, and What You Must Do Right Now

Comments
10 min read
The TanStack npm Attack Shows Why pnpm 11 Matters

The TanStack npm Attack Shows Why pnpm 11 Matters

2
Comments
3 min read
LibKill: Scan Your Machine for Compromised npm, pip, and Bun Packages

LibKill: Scan Your Machine for Compromised npm, pip, and Bun Packages

Comments
3 min read
Mini Shai-Hulud: A persistent supply-chain worm

Mini Shai-Hulud: A persistent supply-chain worm

1
Comments 1
3 min read
The Worm in the Registry

The Worm in the Registry

2
Comments
10 min read
Docker Caching Strategies That Actually Work with npm ci

Docker Caching Strategies That Actually Work with npm ci

Comments
2 min read
Deep Dive: TanStack npm supply-chain compromise

Deep Dive: TanStack npm supply-chain compromise

1
Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.