Tech does not just watch: Take action against Russia’s war on Ukraine 🇺🇦, and take action against Israel’s genocide on the Palestinian people and the destruction of Palestine 🇵🇸 Protest and divest. Hide

Frontend Dogma

“npm” News Archive

Supertopics: , , package-managers · subtopics: ,  (non-exhaustive) · glossary look-up: “npm”

Entry (Sources) and Other Related TopicsDate#
npm “Accidentally” Removes Stylus Package, Breaks Builds and Pipelines (ax/ble)148
eslint-config-prettier Compromised: How npm Package With 30 Million Downloads Spread Malware147
, , ,
npm Phishing Email Targets Developers With Typosquatted Domain (sar/soc)146
Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader (soc)145
,
30 Years of JavaScript: 10 Milestones That Changed the Web (ric/the)144
, , , , , , , , , ,
npm Targeted by Malware Campaign Mimicking Familiar Library Names (soc)143
, , ,
npm Should Remove the Default License From New Packages (ISC) (ext)142
, ,
A Decade of Impact: How Our npm Packages Hit 1 Billion Downloads and Shaped JavaScript141
, ,
Malware Found on npm Infecting Local Package With Reverse Shell (rev)140
,
Lazarus Strikes npm Again With New Wave of Malicious Packages (soc)139
,
@ 11ty/image-color (zac)138
, ,
Tutorial: Publishing ESM-Based npm Packages With TypeScript (rau)137
, ,
Is npm Enough? Why Startups Are Coming After This JavaScript Package Registry (kat/red)136
, , , ,
Keep Your Node.js Apps Secure With “npx is-my-node-vulnerable” (tre)135
, ,
My Failed Attempt to Shrink All npm Packages by 5% (eva)134
,
How I Open-Sourced My Secret Access Tokens From GitHub, Slack, and npm—and Who Actually Cares133
, ,
Mastering npm Scripts: Automate Everything in Your Frontend Workflow132
, , ,
HTML Conformance: A Comparison of 6.5 npm Validator Packages (With 1.5 Recommendations) (j9t)131
, , ,
Publishing a Simple Client-Side JavaScript Package to npm With GitHub Actions (sim)130
, ,
How to Prerelease an npm Package (spa/clo)129
, , ,
Understanding “npm audit” and Fixing Vulnerabilities128
, ,
npm vs. npx127
, ,
Significance of package-lock.json or yarn-lock.json126
,
More npm Packages on Cloudflare Workers: Combining Polyfills and Native Code to Support Node.js APIs (jas+/clo)125
, , ,
caniuse-cli (bra)124
, , , , ,
CSS Style Observer (bra)123
,
How to Create an npm Package (mat)122
,
ObsoHTML, the Obsolete HTML Checker (j9t)121
, ,
The Great npm Garbage Patch120
, ,
Building an “npm create” Package (ach)119
Publishing a TypeScript Module to npm vs. JSR (den)118
, , , , ,
Supply Chain Security in npm—We Can Be Optimistic About the Future117
, ,
Leaner npm Packument (Metadata) Contents (git)116
Create npm Package With CommonJS and ESM Support in TypeScript115
, , ,
npm and Node.js Should Do More to Make ES Modules Easy to Use114
,
What Happens When a Major npm Library Goes Commercial? (mco)113
,
Researchers Uncover npm Registry Vulnerability to Cache Poisoning and DoS Attacks (sar/soc)112
, , ,
How a Single Vulnerability Can Bring Down the JavaScript Ecosystem111
, , , ,
CodeFlattener110
,
Using Vite to Rebuild Local Dependencies in an npm Workspace109
,
Building an npm Package Compatible With ESM and CJS in 2024 (sny)108
, , ,
npm Basics for New Developers (nim)107
Node.js TSC Confirms: No Intention to Remove npm From Distribution (sar/soc)106
The Ultimate Guide to Understanding npx vs. npm105
, ,
eslint-plugin-depend104
, ,
How npm Install Scripts Can Be Weaponized: A Real-World Example of a Harmful npm Package (eth)103
, ,
Why Does “is-number” Package Have 59M Weekly Downloads?102
Node.js Community Debate Intensifies Over Enabling Corepack by Default and Potentially Unbundling npm (sar/soc)101
, , , ,
Malicious npm Package Masquerades as Noblox.js, Targeting Roblox Users for Data Theft (sar/soc)100
,
GitHub, npm Registry Abused to Host SSH Key-Stealing Malware99
, , ,
Modern JavaScript Library Starter98
,
Deceptive Deprecation: The Truth About npm Deprecated Packages97
, ,
npm in Review: A 2023 Retrospective on Growth, Security, and Quirky Facts (soc)96
When “Everything” Becomes Too Much: The npm Package Chaos of 2024 (soc)95
A Comprehensive Guide to npm Workspaces and Monorepos94
, , ,
I Replaced npm, Yarn, and nvm With pnpm (paw)93
, , ,
How to Use npm Packages Outside of Node92
, ,
Secret Scanning Scans Public npm Packages (git)91
, ,
TypeScript Monorepo With npm Workspaces (skw)90
, ,
SSH Keys Stolen by Stream of Malicious PyPI and npm Packages (ble)89
, ,
Honey, I Shrunk the npm Package88
,
npm Provenance General Availability (git)87
, ,
How to Migrate From npm to pnpm86
, ,
dependency-time-machine85
, , ,
Sophisticated, Highly-Targeted Attacks Continue to Plague npm84
Publishing With npm Provenance From Private Source Repositories Is No Longer Supported (git)83
, , ,
Social Engineering Campaign Targeting Tech Employees Spreading Through npm Malware (soc)82
,
A Comprehensive Beginner’s Guide to npm: Simplifying Package Management81
,
Making the Switch: From Yarn/npm to pnpm80
,
Identify Unused npm Packages in Your Project (ami)79
,
The Massive Bug at the Heart of the npm Ecosystem78
,
Create React UI Lib: Component Library Speedrun77
, ,
npm Won’t Publish Packages Containing the Word “keygen”76
,
Comparing the Best Node.js Version Managers: nvm, Volta, and asdf75
,
npm vs. Yarn vs. pnpm74
, ,
Generating Provenance Statements73
,
Introducing npm Package Provenance (git)72
, , , ,
Dissecting npm Malware: Five Packages and Their Evil Install Scripts71
,
Understanding npm Versioning70
, ,
One in Two New npm Packages Is SEO Spam Right Now69
The Landscape of npm Packages for CLI Apps68
, ,
Automatic npm Publishing With GitHub Actions and npm Granular Tokens67
,
Why We Added package.json Support to Deno (tin/den)66
, ,
Speeding Up the JavaScript Ecosystem—npm Scripts (mar)65
, ,
Unlocking Security Updates for Transitive Dependencies With npm (git)64
, ,
Lockfile Trick: Package an npm Project With Nix in 20 Lines63
New npm Features for Secure Publishing and Safe Consumption (git)62
,
Migrating From npm to pnpm61
,
npm Security: Preventing Supply Chain Attacks (sny)60
,
How to Build, Test, and Publish a TypeScript npm Package in 202259
,
Why You Should Prefer Using pnpm Over npm and Yarn?58
, ,
Use “npm query” and jq to Dig Into Your Dependencies57
, ,
Phylum Detects Active Typosquatting Campaign Targeting npm Developers56
,
depngn55
, ,
Best Practices for Creating a Modern npm Package (sny)54
Dependabot Unlocks Transitive Dependencies for npm Projects (git)53
,
4 Ways to Minimize Your Dependencies in Node.js (app)52
,
Installing and Running Node.js Bin Scripts (rau)51
,
Introducing the New npm Dependency Selector Syntax (git)50
Introducing Even More Security Enhancements to npm (git)49
,
Top 5 npm Vulnerability Scanners48
, ,
css-browser-support (5t3)47
, , ,
Imagemin Guard (j9t)46
, , , , , , , ,
Alternatives to Installing npm Packages Globally (rau)45
,
How to Migrate From Yarn/npm to pnpm44
, , ,
You May Not Need a Bundler for Your npm Library43
npm Security Update: Attack Campaign Using Stolen OAuth Tokens (git)42
, , ,
What npm Can Learn From Go41
Snyk Finds 200+ Malicious npm Packages, Including Cobalt Strike Dependency Confusion Attacks (sny)40
, ,
4 Reasons to Avoid Using “npm link”39
How to Respond to Growing Supply Chain Security Risks?38
, , ,
Update Node Dependencies Automatically, Selectively, or Incrementally37
, ,
What’s Really Going On Inside Your node_modules Folder? (soc)36
,
How to Publish Deno Modules to npm (kit/den)35
, , ,
Understanding Dependencies Inside Your package.json (nod)34
, ,
How to Fix Your Security Vulnerabilities With npm Override33
, , ,
The Basics of package.json (nod)32
, , ,
pkg.land31
, ,
GitHub’s Commitment to npm Ecosystem Security (git)30
,
Yarn vs. npm: Everything You Need to Know29
,
timefind28
,
Common npm Mistakes Every Developer Should Avoid27
npm Security Best Practices (owa)26
,
Simple Monorepos via npm Workspaces and TypeScript Project References (rau)25
,
NPM Global Audit24
, , ,
“npm ruin dev” (ada/css)23
, , ,
What Is Node and When Should I Use It?22
,
How to Publish an Updated Version of an npm Package (spa/clo)21
,
How to Add CSS Vendor Prefixes Automatically (luk)20
, , , , , , ,
a11y-syntax-highlighting (eri)19
, ,
How to Worry About npm Package Weight (chr/css)18
Validating Dependencies in the Project With npm-check and depcheck17
, , , ,
Introducing npx: An npm Package Runner (zka)16
, ,
10 Node.js Best Practices: Enlightenment From the Node Gurus15
, , , , , , ,
Why npm Scripts? (css)14
, , , , , , ,
why-is-node-running13
,
How to Solve the Global npm Module Dependency Problem12
,
image-dimensions (sin)11
,
Learning Node.js: The “npm link”10
,
9 Quick Tips About npm9
, ,
Peer Dependencies (dom)8
,
Madge7
, ,
npm Package Checker6
, , , ,
npm Package Download Statistics Checker5
, , , , ,
npm Dependency Visualizer4
, , , , ,
npm Package Types Checker3
, , , , , ,
npm, Yarn, and pnpm Command Converter2
, , , , ,
npm Package Size Checker1
, , , ,