Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
npm
Follow
Hide
Node Package Manager
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
thusdev-fetch atteint 256 téléchargements npm en 2 jours !
Malthus AMETEPE
Malthus AMETEPE
Malthus AMETEPE
Follow
Apr 16
thusdev-fetch atteint 256 téléchargements npm en 2 jours !
#
node
#
javascript
#
opensource
#
npm
3
 reactions
Comments
Add Comment
1 min read
How I responded to a Supply Chain attack before it hit my project
Vinicius de Santana
Vinicius de Santana
Vinicius de Santana
Follow
May 18
How I responded to a Supply Chain attack before it hit my project
#
suplychainatack
#
webdev
#
npm
3
 reactions
Comments
3
 comments
3 min read
My AI told me to pip install a package that doesn't exist. Turns out someone already weaponized that.
Xihe 曦和
Xihe 曦和
Xihe 曦和
Follow
Apr 14
My AI told me to pip install a package that doesn't exist. Turns out someone already weaponized that.
#
ai
#
npm
#
security
#
testing
Comments
Add Comment
2 min read
Lazy SRE's guide to secure systems, part 1: the dependencies you didn't read
Harshit Luthra
Harshit Luthra
Harshit Luthra
Follow
May 18
Lazy SRE's guide to secure systems, part 1: the dependencies you didn't read
#
security
#
lazysre
#
supplychain
#
npm
Comments
Add Comment
7 min read
Le migliori librerie di notifiche per React Native nel 2026: quale scegliere?
Marco Crupi
Marco Crupi
Marco Crupi
Follow
Apr 14
Le migliori librerie di notifiche per React Native nel 2026: quale scegliere?
#
reactnative
#
react
#
opensource
#
npm
Comments
Add Comment
7 min read
Hardening Your npm CI in 5 Concrete Layers
ShipWithAI
ShipWithAI
ShipWithAI
Follow
May 7
Hardening Your npm CI in 5 Concrete Layers
#
claudecode
#
ai
#
npm
#
githubactions
1
 reaction
Comments
Add Comment
2 min read
axios npm Supply Chain Attack (March 31, 2026) — What Happened and How to Check Your Lock File Right Now
LazyDev_OH
LazyDev_OH
LazyDev_OH
Follow
Apr 14
axios npm Supply Chain Attack (March 31, 2026) — What Happened and How to Check Your Lock File Right Now
#
security
#
npm
#
javascript
#
webdev
1
 reaction
Comments
Add Comment
6 min read
Why npm supply chain attacks keep happening and how to harden your installs
Alan West
Alan West
Alan West
Follow
May 17
Why npm supply chain attacks keep happening and how to harden your installs
#
npm
#
security
#
javascript
#
devops
Comments
Add Comment
4 min read
All It Took Was npm install (Axios Attack)
Chioma Halim
Chioma Halim
Chioma Halim
Follow
Apr 13
All It Took Was npm install (Axios Attack)
#
npm
#
webdev
#
cybersecurity
#
node
1
 reaction
Comments
Add Comment
4 min read
Completing the Picture: Adding Memory Diagnostics to a CPU Profiler
Bill Tu
Bill Tu
Bill Tu
Follow
Apr 13
Completing the Picture: Adding Memory Diagnostics to a CPU Profiler
#
npm
#
node
#
javascript
Comments
Add Comment
6 min read
Signals, Effects, and the Algebra Between Them
Ja
Ja
Ja
Follow
Apr 13
Signals, Effects, and the Algebra Between Them
#
typescript
#
npm
#
datastructures
#
node
Comments
Add Comment
6 min read
I audited the top 50 npm packages. Almost none ship with supply-chain attestations!
The Crypto Donkey
The Crypto Donkey
The Crypto Donkey
Follow
Apr 13
I audited the top 50 npm packages. Almost none ship with supply-chain attestations!
#
webdev
#
javascript
#
security
#
npm
Comments
Add Comment
10 min read
No, the AI didn't compromise your npm packages. You did.
PRANTA Dutta
PRANTA Dutta
PRANTA Dutta
Follow
May 15
No, the AI didn't compromise your npm packages. You did.
#
security
#
javascript
#
npm
#
ai
3
 reactions
Comments
1
 comment
13 min read
gpushx: The All-in-One CLI That Made My GitHub + Deployment Workflow 10x Faster
vinnugollakoti
vinnugollakoti
vinnugollakoti
Follow
May 16
gpushx: The All-in-One CLI That Made My GitHub + Deployment Workflow 10x Faster
#
npm
#
cli
#
terminal
#
github
6
 reactions
Comments
Add Comment
2 min read
I Ranked AI SDKs by Supply Chain Risk. LangChain Lost.
Pico
Pico
Pico
Follow
May 5
I Ranked AI SDKs by Supply Chain Risk. LangChain Lost.
#
security
#
javascript
#
npm
#
webdev
1
 reaction
Comments
Add Comment
4 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account