DEV Community

npm

Node Package Manager

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
I Built a Free Supply Chain Scanner After Watching Hermes-Agent Get Infected

I Built a Free Supply Chain Scanner After Watching Hermes-Agent Get Infected

1
Comments
4 min read
Notifee is Archived. Here’s a Maintained, New-Architecture Drop-in Replacement

Notifee is Archived. Here’s a Maintained, New-Architecture Drop-in Replacement

Comments
5 min read
Welcome to Transitive Dependency Hell

Welcome to Transitive Dependency Hell

Comments 1
5 min read
Building a Double-Entry Accounting Engine in Node.js (Open Source — ledgerstack-core)

Building a Double-Entry Accounting Engine in Node.js (Open Source — ledgerstack-core)

1
Comments
2 min read
The Invisible Network Calls: Tracking fetch() and dns.promises in Node.js

The Invisible Network Calls: Tracking fetch() and dns.promises in Node.js

Comments
6 min read
Bear UI v1.1.5: PropsPlayground, PageNav, Button Refactor, and a Polished Portal

Bear UI v1.1.5: PropsPlayground, PageNav, Button Refactor, and a Polished Portal

1
Comments
3 min read
How npm, pnpm, and yarn Ate 40GB of My 256GB SSD

How npm, pnpm, and yarn Ate 40GB of My 256GB SSD

1
Comments
3 min read
Building a Zero-Dependency Rate Limiter for Express: Inside api-rate-guard

Building a Zero-Dependency Rate Limiter for Express: Inside api-rate-guard

1
Comments
6 min read
npm Provenance and SLSA: The Supply Chain Hygiene Baseline Every Team Needs in 2026

npm Provenance and SLSA: The Supply Chain Hygiene Baseline Every Team Needs in 2026

Comments
5 min read
MCP Connector Poisoning: How Compromised npm Packages Hijack Your AI Agent

MCP Connector Poisoning: How Compromised npm Packages Hijack Your AI Agent

Comments 1
5 min read
🕵️‍♂️ Dependencies Should Not Be Silent: Inspect What Your npm Packages Actually Do

🕵️‍♂️ Dependencies Should Not Be Silent: Inspect What Your npm Packages Actually Do

1
Comments
3 min read
OpenClaw npm Malware: Fake Package Deploys GhostLoader RAT

OpenClaw npm Malware: Fake Package Deploys GhostLoader RAT

1
Comments
2 min read
StyleGuard: Keep Your UI Consistent Without Slowing Down Development

StyleGuard: Keep Your UI Consistent Without Slowing Down Development

1
Comments
3 min read
Claude Code's Source Leak Was Embarrassing. The Real Story Is What It Revealed

Claude Code's Source Leak Was Embarrassing. The Real Story Is What It Revealed

3
Comments 1
14 min read
I Built a Zero-Dependency Supply-Chain Security Scanner for Node.js — 18 Checks, One Command

I Built a Zero-Dependency Supply-Chain Security Scanner for Node.js — 18 Checks, One Command

1
Comments 1
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.