DEV Community

npm

Node Package Manager

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
thusdev-fetch atteint 256 téléchargements npm en 2 jours !

thusdev-fetch atteint 256 téléchargements npm en 2 jours !

3
Comments
1 min read
How I responded to a Supply Chain attack before it hit my project

How I responded to a Supply Chain attack before it hit my project

3
Comments 3
3 min read
My AI told me to pip install a package that doesn't exist. Turns out someone already weaponized that.

My AI told me to pip install a package that doesn't exist. Turns out someone already weaponized that.

Comments
2 min read
Lazy SRE's guide to secure systems, part 1: the dependencies you didn't read

Lazy SRE's guide to secure systems, part 1: the dependencies you didn't read

Comments
7 min read
Le migliori librerie di notifiche per React Native nel 2026: quale scegliere?

Le migliori librerie di notifiche per React Native nel 2026: quale scegliere?

Comments
7 min read
Hardening Your npm CI in 5 Concrete Layers

Hardening Your npm CI in 5 Concrete Layers

1
Comments
2 min read
axios npm Supply Chain Attack (March 31, 2026) — What Happened and How to Check Your Lock File Right Now

axios npm Supply Chain Attack (March 31, 2026) — What Happened and How to Check Your Lock File Right Now

1
Comments
6 min read
Why npm supply chain attacks keep happening and how to harden your installs

Why npm supply chain attacks keep happening and how to harden your installs

Comments
4 min read
All It Took Was npm install (Axios Attack)

All It Took Was npm install (Axios Attack)

1
Comments
4 min read
Completing the Picture: Adding Memory Diagnostics to a CPU Profiler

Completing the Picture: Adding Memory Diagnostics to a CPU Profiler

Comments
6 min read
Signals, Effects, and the Algebra Between Them

Signals, Effects, and the Algebra Between Them

Comments
6 min read
I audited the top 50 npm packages. Almost none ship with supply-chain attestations!

I audited the top 50 npm packages. Almost none ship with supply-chain attestations!

Comments
10 min read
No, the AI didn't compromise your npm packages. You did.

No, the AI didn't compromise your npm packages. You did.

3
Comments 1
13 min read
gpushx: The All-in-One CLI That Made My GitHub + Deployment Workflow 10x Faster

gpushx: The All-in-One CLI That Made My GitHub + Deployment Workflow 10x Faster

6
Comments
2 min read
I Ranked AI SDKs by Supply Chain Risk. LangChain Lost.

I Ranked AI SDKs by Supply Chain Risk. LangChain Lost.

1
Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.