DEV Community

npm

Node Package Manager

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Add a 50x+ faster duplicate-code gate to GitHub Actions with jscpd-rs

Add a 50x+ faster duplicate-code gate to GitHub Actions with jscpd-rs

3
Comments
5 min read
Four MCP packages, four ways the supply chain shifted in two weeks of npm monitoring

Four MCP packages, four ways the supply chain shifted in two weeks of npm monitoring

Comments
7 min read
You've probably never heard of these npm packages. They're in your production app.

You've probably never heard of these npm packages. They're in your production app.

Comments
3 min read
Hardening npm dependency security

Hardening npm dependency security

Comments
4 min read
Three npm Disasters That Were Predictable (And What the Signals Looked Like)

Three npm Disasters That Were Predictable (And What the Signals Looked Like)

1
Comments
6 min read
I audited 25 top npm packages with a zero-install CLI. Here's who passes.

I audited 25 top npm packages with a zero-install CLI. Here's who passes.

1
Comments
4 min read
I Built a 8.7KB React Animation Library (120+ FPS) on top of GSAP

I Built a 8.7KB React Animation Library (120+ FPS) on top of GSAP

3
Comments
1 min read
We analysed 396 breaking dependency releases. Here's what they have in common.

GitHub “Finish-Up-A-Thon” Challenge Submission

We analysed 396 breaking dependency releases. Here's what they have in common.

Comments
3 min read
When GitHub Actions Goes Silent: The Pending-Forever Bug I Hit Shipping My MCP Server to npm

When GitHub Actions Goes Silent: The Pending-Forever Bug I Hit Shipping My MCP Server to npm

Comments
5 min read
AI Hallucinated Dependencies Are the New Supply Chain Attack: How to Stop Them

AI Hallucinated Dependencies Are the New Supply Chain Attack: How to Stop Them

Comments
8 min read
`npm fund`

`npm fund`

1
Comments
1 min read
How to Automate OTP Extraction and Email Testing in n8n with Disposable Inboxes

How to Automate OTP Extraction and Email Testing in n8n with Disposable Inboxes

Comments
3 min read
smart-seo-lite — a lightweight npm package

smart-seo-lite — a lightweight npm package

1
Comments
1 min read
AI is writing our code... but who is auditing the AI?

AI is writing our code... but who is auditing the AI?

Comments
3 min read
Two Types of npm Supply Chain Attack: What Catches Each

Two Types of npm Supply Chain Attack: What Catches Each

Comments
5 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.