Life is about deciding who you are: Join us and decide to be for environmental protection, free education and generous social security, human rights and international law, and, of course, action against oppression and violence (starting with helping the people of occupied Palestine 🇵🇸)! Hide

Frontend Dogma

“dependencies” News Archive

Definition, related topics, and tag feed

Definition · Subtopics: dependabot, depfu, packages, renovate (non-exhaustive) · “dependencies” RSS feed (per email)

Entry (Sources) and Additional TopicsDate#
Supply-Chain Attack Using Invisible Code Hits GitHub and Other Repositories (dan/ars)169
security, github
Node.js Package Configuration Guide (nod)168
guides, packages, configuration, commonjs, esm
Web Dependencies Are Broken—Can We Fix Them? (lea)167
javascript, import-maps, web-platform
npm to Implement Staged Publishing After Turbulent Shift Off Classic Tokens (sar/soc)166
npm, security, github
The Nine Levels of JavaScript Dependency Hell (and)165
javascript, maintainability
The Package Management Landscape (and)164
tooling, overviews, link-lists
How We’re Protecting Our Newsroom From npm Supply Chain Attacks (rya/pnp)163
npm, security, case-studies
No More Tokens—Locking Down npm Publish Workflows (zac)162
npm, security, github, processes
The Shai-Hulud 2.0 npm Worm: Analysis, and What You Need to Know161
npm, security
GitLab Discovers Widespread npm Supply Chain Attack (git)160
npm, security, gitlab, github, aws, gcp, azure
Shipping Node.js Packages in 2025 (joy)159
slides, nodejs, esm, commonjs
15 Recent Node.js Features That Replace Popular npm Packages (nod)158
nodejs, npm, maintenance
Principles of Simplicity in Frontend Architecture157
simplicity, principles
What Just Happened to RubyGems? (chr)156
ruby, shopify
Our Plan for a More Secure npm Supply Chain (xco/git)155
npm, security, foss
This May Be the Worst One (the)154
videos, npm, security
Ongoing Supply Chain Attack Targets CrowdStrike npm Packages (pvd+/soc)153
npm, security
ctrl/tinycolor and 40+ npm Packages Compromised152
npm, security
Which npm Package Has the Largest Version Number?151
npm, versioning, semver
How to Keep package.json Under Control (tmc/val)150
how-tos, nodejs, npm, maintainability
Oh No, Not Again… a Meditation on npm Supply Chain Attacks (tan)149
npm, security, microsoft
Anatomy of a Billion-Download npm Supply-Chain Attack148
npm, security
npm Author Qix Compromised via Phishing Email in Major Supply Chain Attack (bur+/soc)147
npm, security
Why You Absolutely Need to Have Automated Dependency Management in Place (j9t)146
maintainability, maintenance, security, automation, tooling
Speeding Up the JavaScript Ecosystem—SemVer (mar)145
javascript, performance, semver, versioning
npm Trusted Publishing With OIDC Is Generally Available (git)144
npm, provenance, github
Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader (soc)143
security, npm
Ramblings on Dependency Management (mpl)142
maintenance
npm Targeted by Malware Campaign Mimicking Familiar Library Names (soc)141
npm, malware, security, link-lists
npm Should Remove the Default License From New Packages (ISC) (ext)140
npm, licensing, foss
Eleventy: A GitHub Workflow to Check if an Automated Dependency Update Would Break Your Site (j9t)139
eleventy, nodejs, automation, github-actions
LLMs Can’t Stop Making Up Software Dependencies and Sabotaging Everything (tho/the)138
ai, security, slop
A Decade of Impact: How Our npm Packages Hit 1 Billion Downloads and Shaped JavaScript137
npm, history, javascript
Breaking Down Circular Dependencies in JavaScript136
javascript
Malware Found on npm Infecting Local Package With Reverse Shell (rev)135
npm, security
Lazarus Strikes npm Again With New Wave of Malicious Packages (soc)134
npm, security
Tutorial: Publishing ESM-Based npm Packages With TypeScript (rau)133
tutorials, npm, typescript
My Failed Attempt to Shrink All npm Packages by 5% (eva)132
npm, compression
Build It Yourself (mit)131
maintenance, maintainability, processes
10 Very Important Flutter Packages130
flutter
Double-Keyed Caching: How Browser Cache Partitioning Changed the Web (add)129
browsers, caching, network, content-delivery, performance
Do I Need This Node Dependency? (bri)128
nodejs
The 20 Commandments of Software Engineering127
principles, programming, complexity, documentation, commit-messages, code-reviews, maintenance, collaboration
On Long Term Software Development (ber)126
maintainability, maintenance, foss, testing, complexity
Mastering npm Scripts: Automate Everything in Your Frontend Workflow125
npm, environments, ci-cd, automation
JS Import Maps (5t3)124
javascript, import-maps
Your JavaScript Bundle Is Too Fat123
javascript, bundling, performance, code-splitting, lazy-loading, tree-shaking, minification, optimization
Publishing a Simple Client-Side JavaScript Package to npm With GitHub Actions (sim)122
javascript, npm, github-actions
How to Prerelease an npm Package (spa/clo)121
how-tos, npm, versioning, semver
Node.js Corepack: Version Control for Package Managers (tre)120
nodejs, corepack, versioning, tooling
Introducing the vlt Package Manager and Serverless Registry119
introductions, serverless, javascript, tooling
cpx—the npx Counterpart of the PHP Ecosystem (ami)118
php
The Nine Node Pillars (mco/pla)117
nodejs, principles
More npm Packages on Cloudflare Workers: Combining Polyfills and Native Code to Support Node.js APIs (jas+/clo)116
cloudflare, nodejs, npm, apis
Hidden Cost of Frontend Frameworks115
frameworks, simplicity
How to Create an npm Package (mat)114
how-tos, npm
The Great npm Garbage Patch113
npm, spam, security
Secure Node.js Applications From Supply Chain Attacks112
nodejs, security, best-practices
Publishing a TypeScript Module to npm vs. JSR (den)111
videos, typescript, modules, npm, jsr, comparisons
Supply Chain Security in npm—We Can Be Optimistic About the Future110
npm, security, provenance
Create npm Package With CommonJS and ESM Support in TypeScript109
npm, commonjs, esm, typescript
What Happens When a Major npm Library Goes Commercial? (mco)108
npm, foss
Dual Publishing ESM and CJS Modules With tsup and “Are the Types Wrong?” (joh)107
esm, commonjs, tooling, typescript, type-safety
Researchers Uncover npm Registry Vulnerability to Cache Poisoning and DoS Attacks (sar/soc)106
npm, vulnerabilities, caching, security
How a Single Vulnerability Can Bring Down the JavaScript Ecosystem105
javascript, npm, caching, vulnerabilities, security
How to Use Corepack (mat)104
how-tos, nodejs, corepack
JSR: The JavaScript Package Registry We’ve Been Waiting For103
jsr
JavaScript Security: Simple Practices to Secure Your Frontend102
javascript, security, csp
How to Document Your JavaScript Package (den)101
how-tos, javascript, documentation, writing, jsdoc, readme
JSR Is Not Another Package Manager (tin/den)100
jsr
Using Vite to Rebuild Local Dependencies in an npm Workspace99
npm, vite
Building an npm Package Compatible With ESM and CJS in 202498
npm, interoperability, esm, commonjs
Microservices Promised Freedom but Delivered Dependencies (pur)97
microservices
Another JS Registry—Seriously?! (den)96
videos, jsr, javascript
How npm Install Scripts Can Be Weaponized: A Real-World Example of a Harmful npm Package (eth)95
npm, examples, security
Introducing JSR—the JavaScript Registry (lca+/den)94
introductions, jsr, deno, javascript
Choosing the Right Node.js Package Manager in 2024: A Comparative Guide (nod)93
guides, nodejs, comparisons
Why Does “is-number” Package Have 59M Weekly Downloads?92
npm
JSR: What We Know So Far About Deno’s New JavaScript Package Registry (sar/soc)91
jsr, deno, javascript
Frontend Application Security: Tips and Tricks90
web-apps, security, xss, csrf, authentication, csp, validation, tips-and-tricks
Node.js Community Debate Intensifies Over Enabling Corepack by Default and Potentially Unbundling npm (sar/soc)89
nodejs, corepack, npm, yarn, pnpm
Malicious npm Package Masquerades as Noblox.js, Targeting Roblox Users for Data Theft (sar/soc)88
npm, security
Modern JavaScript Library Starter87
npm, libraries
Deceptive Deprecation: The Truth About npm Deprecated Packages86
deprecation, security, npm, research
Compatibility of Node.js Versions With Packages85
nodejs, versioning
Installing Google Fonts as npm Packages (ami)84
installing, tooling, google, fonts
A Comprehensive Guide to npm Workspaces and Monorepos83
guides, monorepos, npm, yarn
I Replaced npm, Yarn, and nvm With pnpm (paw)82
npm, yarn, pnpm, nvm
A Complete Guide to pnpm81
guides, pnpm
Understanding Dev Dependencies in Web Development80
How to Use npm Packages Outside of Node79
how-tos, npm, javascript
Secret Scanning Scans Public npm Packages (git)78
github, npm, security
How We Optimized Package Imports in Next.js77
nextjs, optimization, case-studies
Honey, I Shrunk the npm Package76
npm, compression
SSH Keys Stolen by Stream of Malicious PyPI and npm Packages (ble)75
security, ssh, npm
Upgrading Frontend Dependencies With Confidence74
maintenance, testing, regressions, playwright
Bun Hype: How We Learned Nothing From Yarn73
bun, yarn, history
dependency-time-machine72
packages, npm, maintenance, automation
My Experience Modernizing Packages to ESM71
modernization, esm
A Comprehensive Beginner’s Guide to npm: Simplifying Package Management70
guides, npm
Identify Unused npm Packages in Your Project (ami)69
npm, maintenance
The Massive Bug at the Heart of the npm Ecosystem68
npm, security, bugs
It Depends—Exploring My Favourite Renovate Features for Dependency Updates (kal)67
maintenance, renovate, configuration
npm Won’t Publish Packages Containing the Word “keygen”66
discussions, npm
Before Your Next Frontend Pull Request, Use This Checklist (tra/evi)65
checklists, performance, compression, accessibility, legibility, naming
Building a Frontend Framework—Reactivity and Composability With Zero Dependencies64
frameworks, reactivity
The Case Against Automatic Dependency Updates (ben)63
automation, ci-cd, maintenance, security
Automating Dependency Updates: The Big Debate62
automation, ci-cd, security
Deno vs. Node: No One Is Ready for the Move61
deno, nodejs, comparisons
Understanding npm Versioning60
npm, versioning, semver
The Landscape of npm Packages for CLI Apps59
nodejs, npm, command-line
npx: The Easy Way to Run Node.js Packages58
nodejs, npx
Node.js Toolbox57
websites, nodejs, packages
Unlocking Security Updates for Transitive Dependencies With npm (git)56
npm, security, maintenance
Using Renovate With Codeberg (nic)55
codeberg, maintenance, renovate
New npm Features for Secure Publishing and Safe Consumption (git)54
npm, security
npm Security: Preventing Supply Chain Attacks53
npm, security
Use “npm query” and jq to Dig Into Your Dependencies52
videos, npm, auditing
Phylum Detects Active Typosquatting Campaign Targeting npm Developers51
npm, security
depngn50
packages, npm, nodejs
Dependabot Unlocks Transitive Dependencies for npm Projects (git)49
npm, security, dependabot
4 Ways to Minimize Your Dependencies in Node.js (app)48
nodejs, npm
JavaScript Bugs Aplenty in Node.js Ecosystem—Found Automatically47
studies, research, nodejs, javascript, security, quality, bugs
Everything You Need to Know About JavaScript Import Maps (hon)46
javascript, import-maps
Optimizing Node.js Dependencies in AWS Lambda (aws)45
nodejs, aws, serverless, lambda, optimization
Alternatives to Installing npm Packages Globally (rau)44
installing, npm
Sponsoring Dependencies: The Next Step in Open Source Sustainability (nza)43
economics, foss
Don’t Sink Your Website With Third Parties (sma)42
embed-code, performance
Snyk Finds 200+ Malicious npm Packages, Including Cobalt Strike Dependency Confusion Attacks41
javascript, npm, security
Lerna Has Gone—Which Monorepo Is Right for a Node.js Backend Now?40
monorepos, comparisons, nodejs, lerna
8 Industry-Standard Tools to Reduce Dependency Risks39
tooling, maintenance, renovate, depfu, link-lists
How to Respond to Growing Supply Chain Security Risks?38
how-tos, security, nodejs, npm
On the Weaponisation of Open Source (ben)37
foss, mongodb, nodejs
Update Node Dependencies Automatically, Selectively, or Incrementally36
nodejs, npm, yarn
What’s Really Going On Inside Your node_modules Folder? (soc)35
nodejs, npm
How to Publish Deno Modules to npm (kit/den)34
how-tos, deno, modules, npm
Understanding Dependencies Inside Your package.json (nod)33
nodejs, npm, yarn
How to Fix Your Security Vulnerabilities With npm Override32
how-tos, security, vulnerabilities, npm
The Basics of package.json (nod)31
fundamentals, nodejs, npm, yarn
How to Keep Your Repo Package Dependencies Up to Date Automatically30
how-tos, tooling, github-actions
Dependency Risk and Funding (mit)29
github, economics
pkg.land28
websites, packages, npm
Why You Should Check in Your Node Dependencies27
nodejs
Ain’t No Party Like a Third Party (ada/css)26
embed-code, security
Open Source Insights25
websites, foss, security, licensing
Use Depfu and Mergify to Automatically Merge Dependency Updates24
maintenance, automation, depfu
Find Unused npm Dependencies23
packages
Uninstalling Dev Dependencies With npm22
npm
Why We Developed the Node.js Reference Architecture21
nodejs, architecture
Automated Dependency Management With Depfu (the)20
automation, depfu
How to Publish an Updated Version of an npm Package (spa/clo)19
how-tos, npm
How to Automatically Update Your JavaScript Dependencies (spa/clo)18
how-tos, javascript, automation, processes, security
How to Worry About npm Package Weight (chr/css)17
npm
Lerna: A Tale of Renaming npm Packages16
refactoring, npm, lerna
Validating Dependencies in the Project With npm-check and depcheck15
security, maintenance, auditing, tooling, npm
HTML, CSS, and Dependency Direction (j9t)14
html, css, maintainability, best-practices
Distribution Packages Considered Insecure13
unix-like, security
How to Solve the Global npm Module Dependency Problem12
how-tos, npm
The Tedium of Managing Code (lyz/ali)11
maintenance, maintainability, javascript, tooling
Peer Dependencies (dom)10
npm, nodejs
Madge9
packages, npm, visualization
Sprockets: Build Time JavaScript Dependency Management (dal/aja)8
tooling, javascript, ruby
Dealing With Dependencies (tro)7
php
npm Package Size Checker6
tools, exploration, auditing, debugging, npm
npm Package Types Checker5
tools, exploration, auditing, debugging, npm, typescript, type-safety
npm Dependency Visualizer4
tools, exploration, auditing, debugging, npm, visualization
npm Package Download Statistics Checker3
tools, exploration, auditing, debugging, npm, metrics
npm Package Checker2
tools, exploration, auditing, debugging, npm
Dependencies Badge Generator1
tools, exploration, images, npm