close

DEV Community

npm

Node Package Manager

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Launching gh-dep-risk: a GitHub CLI extension for npm dependency PR review

Launching gh-dep-risk: a GitHub CLI extension for npm dependency PR review

Comments
1 min read
thusdev-fetch atteint 256 téléchargements npm en 2 jours !

thusdev-fetch atteint 256 téléchargements npm en 2 jours !

Image 3
Comments
1 min read
My AI told me to pip install a package that doesn't exist. Turns out someone already weaponized that.

My AI told me to pip install a package that doesn't exist. Turns out someone already weaponized that.

Comments
2 min read
The Best Notification Libraries for React Native in 2026: Which One Should You Choose?

The Best Notification Libraries for React Native in 2026: Which One Should You Choose?

Comments
8 min read
Le migliori librerie di notifiche per React Native nel 2026: quale scegliere?

Le migliori librerie di notifiche per React Native nel 2026: quale scegliere?

Comments
7 min read
npm run dev

npm run dev

Image 1
Comments
1 min read
npm audit --json Is Unreadable. I Wrote a Formatter With Zero Dependencies.

npm audit --json Is Unreadable. I Wrote a Formatter With Zero Dependencies.

Image 2
Comments
8 min read
axios npm Supply Chain Attack (March 31, 2026) — What Happened and How to Check Your Lock File Right Now

axios npm Supply Chain Attack (March 31, 2026) — What Happened and How to Check Your Lock File Right Now

Image 1
Comments
6 min read
All It Took Was npm install (Axios Attack)

All It Took Was npm install (Axios Attack)

Image 1
Comments
4 min read
Completing the Picture: Adding Memory Diagnostics to a CPU Profiler

Completing the Picture: Adding Memory Diagnostics to a CPU Profiler

Comments
6 min read
Signals, Effects, and the Algebra Between Them

Signals, Effects, and the Algebra Between Them

Comments
6 min read
I audited the top 50 npm packages. Almost none ship with supply-chain attestations!

I audited the top 50 npm packages. Almost none ship with supply-chain attestations!

Comments
10 min read
I just hardened my OSS release pipeline to 11 layers of security — here's the playbook

I just hardened my OSS release pipeline to 11 layers of security — here's the playbook

Comments
7 min read
I Built a Free API That Checks Package Health for AI Agents

I Built a Free API That Checks Package Health for AI Agents

Comments 1
3 min read
Rust Binary Distribution via npm: Addressing Security Risks and Installation Failures with Native Caching Solutions

Rust Binary Distribution via npm: Addressing Security Risks and Installation Failures with Native Caching Solutions

Comments
12 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.