Tech does not just watch: Take action against Russia’s war on Ukraine 🇺🇦, and take action against Israel’s occupation, destruction, and ethnic cleansing of Palestine (history) 🇵🇸 Hide

Frontend Dogma

“npm” News Archive

Definition, related topics, and tag feed

Definition · Supertopics: nodejs, github, package-managers · Subtopics: npx, packages (non-exhaustive) · “npm” RSS feed (per email)

Entry (Sources) and Additional TopicsDate#
npm to Implement Staged Publishing After Turbulent Shift Off Classic Tokens (sar/soc)175
dependencies, security, github
How We’re Protecting Our Newsroom From npm Supply Chain Attacks (rya/pnp)174
dependencies, security, case-studies
No More Tokens—Locking Down npm Publish Workflows (zac)173
dependencies, security, github, processes
The Shai-Hulud 2.0 npm Worm: Analysis, and What You Need to Know172
security, dependencies
GitLab Discovers Widespread npm Supply Chain Attack (git)171
dependencies, security, gitlab, github, aws, gcp, azure
Automated npm Secret Rotation in GitHub Actions (mhe)170
security, automation, github-actions
Will npm’s New Security Steps Stop Attacks? (rev)169
security, github, maintenance, foss
The State of Node.js 2025 Explained by Its TSC Member (mco/git)168
videos, nodejs
15 Recent Node.js Features That Replace Popular npm Packages (nod)167
nodejs, dependencies, maintenance
How Deno Protects Against npm Exploits (den)166
deno, security
Strengthening npm Security: Important Changes to Authentication and Token Management (git)165
security
Mastering npx: A Cheatsheet for npm and Node.js Power Users164
npx, cheat-sheets, examples, nodejs
Our Plan for a More Secure npm Supply Chain (xco/git)163
dependencies, security, foss
npm Security Best Practices162
security, provenance, best-practices
This May Be the Worst One (the)161
videos, dependencies, security
Ongoing Supply Chain Attack Targets CrowdStrike npm Packages (pvd+/soc)160
dependencies, security
ctrl/tinycolor and 40+ npm Packages Compromised159
dependencies, security
Which npm Package Has the Largest Version Number?158
dependencies, versioning, semver
How to Keep package.json Under Control (tmc/val)157
how-tos, nodejs, dependencies, maintainability
Oh No, Not Again… a Meditation on npm Supply Chain Attacks (tan)156
dependencies, security, microsoft
Anatomy of a Billion-Download npm Supply-Chain Attack155
security, dependencies
npm Author Qix Compromised via Phishing Email in Major Supply Chain Attack (bur+/soc)154
security, dependencies
npm Trusted Publishing With OIDC Is Generally Available (git)153
dependencies, provenance, github
npm “Accidentally” Removes Stylus Package, Breaks Builds and Pipelines (ax/ble)152
stylus
eslint-config-prettier Compromised: How npm Package With 30 Million Downloads Spread Malware151
prettier, eslint, security, malware
npm Phishing Email Targets Developers With Typosquatted Domain (sar/soc)150
security
Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader (soc)149
security, dependencies
30 Years of JavaScript: 10 Milestones That Changed the Web (ric/the)148
javascript, anniversaries, history, ecmascript, ajax, jquery, web-2.0, nodejs, react, typescript, webassembly
npm Targeted by Malware Campaign Mimicking Familiar Library Names (soc)147
malware, security, dependencies, link-lists
npm Should Remove the Default License From New Packages (ISC) (ext)146
dependencies, licensing, foss
A Decade of Impact: How Our npm Packages Hit 1 Billion Downloads and Shaped JavaScript145
dependencies, history, javascript
Malware Found on npm Infecting Local Package With Reverse Shell (rev)144
dependencies, security
Lazarus Strikes npm Again With New Wave of Malicious Packages (soc)143
dependencies, security
@ 11ty/image-color (zac)142
packages, images, colors
Tutorial: Publishing ESM-Based npm Packages With TypeScript (rau)141
tutorials, dependencies, typescript
Is npm Enough? Why Startups Are Coming After This JavaScript Package Registry (kat/red)140
jsr, bun, pnpm, yarn, javascript
Keep Your Node.js Apps Secure With “npx is-my-node-vulnerable” (tre)139
packages, nodejs, security
My Failed Attempt to Shrink All npm Packages by 5% (eva)138
dependencies, compression
How I Open-Sourced My Secret Access Tokens From GitHub, Slack, and npm—and Who Actually Cares137
security, github, slack
Mastering npm Scripts: Automate Everything in Your Frontend Workflow136
dependencies, environments, ci-cd, automation
HTML Conformance: A Comparison of 6.5 npm Validator Packages (With 1.5 Recommendations) (j9t)135
html, conformance, tooling, comparisons
Publishing a Simple Client-Side JavaScript Package to npm With GitHub Actions (sim)134
dependencies, javascript, github-actions
How to Prerelease an npm Package (spa/clo)133
how-tos, dependencies, versioning, semver
Understanding “npm audit” and Fixing Vulnerabilities132
security, vulnerabilities, nodejs
npm vs. npx131
nodejs, npx, comparisons
Significance of package-lock.json or yarn-lock.json130
yarn, comparisons
More npm Packages on Cloudflare Workers: Combining Polyfills and Native Code to Support Node.js APIs (jas+/clo)129
cloudflare, nodejs, apis, dependencies
caniuse-cli (bra)128
packages, support, browsers, web-platform, caniuse, command-line
CSS Style Observer (bra)127
packages, css
How to Create an npm Package (mat)126
how-tos, dependencies
ObsoHTML, the Obsolete HTML Checker (j9t)125
packages, html, quality
The Great npm Garbage Patch124
dependencies, spam, security
Building an “npm create” Package (ach)123
Publishing a TypeScript Module to npm vs. JSR (den)122
videos, typescript, modules, dependencies, jsr, comparisons
Leaner npm Packument (Metadata) Contents (git)121
Supply Chain Security in npm—We Can Be Optimistic About the Future120
dependencies, security, provenance
Create npm Package With CommonJS and ESM Support in TypeScript119
dependencies, commonjs, esm, typescript
npm and Node.js Should Do More to Make ES Modules Easy to Use118
nodejs, esm
What Happens When a Major npm Library Goes Commercial? (mco)117
dependencies, foss
Researchers Uncover npm Registry Vulnerability to Cache Poisoning and DoS Attacks (sar/soc)116
dependencies, vulnerabilities, caching, security
How a Single Vulnerability Can Bring Down the JavaScript Ecosystem115
javascript, dependencies, caching, vulnerabilities, security
CodeFlattener114
packages, javascript
Using Vite to Rebuild Local Dependencies in an npm Workspace113
dependencies, vite
Building an npm Package Compatible With ESM and CJS in 2024112
dependencies, interoperability, esm, commonjs
npm Basics for New Developers (nim)111
fundamentals
Node.js TSC Confirms: No Intention to Remove npm From Distribution (sar/soc)110
nodejs
The Ultimate Guide to Understanding npx vs. npm109
guides, npx, nodejs
eslint-plugin-depend108
packages, maintenance, simplicity
How npm Install Scripts Can Be Weaponized: A Real-World Example of a Harmful npm Package (eth)107
dependencies, examples, security
Why Does “is-number” Package Have 59M Weekly Downloads?106
dependencies
Node.js Community Debate Intensifies Over Enabling Corepack by Default and Potentially Unbundling npm (sar/soc)105
nodejs, corepack, yarn, pnpm, dependencies
Malicious npm Package Masquerades as Noblox.js, Targeting Roblox Users for Data Theft (sar/soc)104
dependencies, security
GitHub, npm Registry Abused to Host SSH Key-Stealing Malware103
github, security, malware, foss
Modern JavaScript Library Starter102
dependencies, libraries
Deceptive Deprecation: The Truth About npm Deprecated Packages101
deprecation, security, dependencies, research
npm in Review: A 2023 Retrospective on Growth, Security, and Quirky Facts (soc)100
retrospectives
When “Everything” Becomes Too Much: The npm Package Chaos of 2024 (soc)99
foss
A Comprehensive Guide to npm Workspaces and Monorepos98
guides, monorepos, yarn, dependencies
I Replaced npm, Yarn, and nvm With pnpm (paw)97
dependencies, yarn, pnpm, nvm
How to Use npm Packages Outside of Node96
how-tos, dependencies, javascript
Secret Scanning Scans Public npm Packages (git)95
github, dependencies, security
TypeScript Monorepo With npm Workspaces (skw)94
monorepos, typescript, architecture
Honey, I Shrunk the npm Package93
dependencies, compression
SSH Keys Stolen by Stream of Malicious PyPI and npm Packages (ble)92
security, ssh, dependencies
npm Provenance General Availability (git)91
github, provenance, security
How to Migrate From npm to pnpm90
how-tos, migrating, pnpm
dependency-time-machine89
packages, dependencies, maintenance, automation
Sophisticated, Highly-Targeted Attacks Continue to Plague npm88
security
Publishing With npm Provenance From Private Source Repositories Is No Longer Supported (git)87
github, provenance, security, foss
Social Engineering Campaign Targeting Tech Employees Spreading Through npm Malware (soc)86
security, malware
A Comprehensive Beginner’s Guide to npm: Simplifying Package Management85
guides, dependencies
Making the Switch: From Yarn/npm to pnpm84
yarn, pnpm
Identify Unused npm Packages in Your Project (ami)83
dependencies, maintenance
Comparing npm, Yarn, and pnpm Package Managers: Which One Is Right for Your Distributed Project to Handle High Loads?82
yarn, pnpm, comparisons, performance, best-practices
The Massive Bug at the Heart of the npm Ecosystem81
dependencies, security
Create React UI Lib: Component Library Speedrun80
typescript, react, components
npm Won’t Publish Packages Containing the Word “keygen”79
discussions, dependencies
Comparing the Best Node.js Version Managers: nvm, Volta, and asdf78
nodejs, nvm
npm vs. Yarn vs. pnpm77
yarn, pnpm, comparisons
Generating Provenance Statements76
provenance, security
Introducing npm Package Provenance (git)75
introductions, github, provenance, security, foss
Dissecting npm Malware: Five Packages and Their Evil Install Scripts74
security, malware
Understanding npm Versioning73
dependencies, versioning, semver
One in Two New npm Packages Is SEO Spam Right Now72
seo
The Landscape of npm Packages for CLI Apps71
nodejs, dependencies, command-line
Automatic npm Publishing With GitHub Actions and npm Granular Tokens70
github-actions, automation
Why We Added package.json Support to Deno (tin/den)69
deno, support, nodejs
Speeding Up the JavaScript Ecosystem—npm Scripts (mar)68
javascript, performance, bundling
Unlocking Security Updates for Transitive Dependencies With npm (git)67
dependencies, security, maintenance
Lockfile Trick: Package an npm Project With Nix in 20 Lines66
tips-and-tricks
New npm Features for Secure Publishing and Safe Consumption (git)65
security, dependencies
Migrating From npm to pnpm64
migrating, pnpm
npm Security: Preventing Supply Chain Attacks63
dependencies, security
How to Build, Test, and Publish a TypeScript npm Package in 202262
how-tos, typescript
Why You Should Prefer Using pnpm Over npm and Yarn?61
pnpm, yarn, comparisons
Use “npm query” and jq to Dig Into Your Dependencies60
videos, dependencies, auditing
Phylum Detects Active Typosquatting Campaign Targeting npm Developers59
dependencies, security
depngn58
packages, nodejs, dependencies
Best Practices for Creating a Modern npm Package57
best-practices
Dependabot Unlocks Transitive Dependencies for npm Projects (git)56
dependencies, security, dependabot
4 Ways to Minimize Your Dependencies in Node.js (app)55
nodejs, dependencies
Installing and Running Node.js Bin Scripts (rau)54
installing, nodejs
Introducing the New npm Dependency Selector Syntax (git)53
introductions
Introducing Even More Security Enhancements to npm (git)52
introductions, security
Top 5 npm Vulnerability Scanners51
security, vulnerabilities, tooling
css-browser-support (5t3)50
packages, css, browsers, support
Imagemin Guard (j9t)49
packages, images, compression, performance, jpeg, png, gif, webp, avif
Alternatives to Installing npm Packages Globally (rau)48
installing, dependencies
How to Migrate From Yarn/npm to pnpm47
how-tos, migrating, yarn, pnpm
You May Not Need a Bundler for Your npm Library46
bundling
npm Security Update: Attack Campaign Using Stolen OAuth Tokens (git)45
security, oauth, version-control, github
What npm Can Learn From Go44
Snyk Finds 200+ Malicious npm Packages, Including Cobalt Strike Dependency Confusion Attacks43
javascript, dependencies, security
4 Reasons to Avoid Using “npm link”42
How to Respond to Growing Supply Chain Security Risks?41
how-tos, security, dependencies, nodejs
Update Node Dependencies Automatically, Selectively, or Incrementally40
nodejs, dependencies, yarn
What’s Really Going On Inside Your node_modules Folder? (soc)39
nodejs, dependencies
How to Publish Deno Modules to npm (kit/den)38
how-tos, deno, modules, dependencies
Understanding Dependencies Inside Your package.json (nod)37
nodejs, dependencies, yarn
How to Fix Your Security Vulnerabilities With npm Override36
how-tos, security, vulnerabilities, dependencies
The Basics of package.json (nod)35
fundamentals, nodejs, dependencies, yarn
pkg.land34
websites, packages, dependencies
GitHub’s Commitment to npm Ecosystem Security (git)33
github, security
Yarn vs. npm: Everything You Need to Know32
yarn, comparisons
timefind31
packages, history
Common npm Mistakes Every Developer Should Avoid30
mistakes
npm Security Best Practices (owa)29
security, best-practices
Simple Monorepos via npm Workspaces and TypeScript Project References (rau)28
monorepos, typescript
NPM Global Audit27
packages, security, quality, auditing
Uninstalling Dev Dependencies With npm26
dependencies
“npm ruin dev” (ada/css)25
html, css, javascript, nodejs
What Is Node and When Should I Use It?24
nodejs, javascript
How to Publish an Updated Version of an npm Package (spa/clo)23
how-tos, dependencies
How to Add CSS Vendor Prefixes Automatically (luk)22
how-tos, css, vendor-extensions, automation, tooling, postcss, webpack, gulp
a11y-syntax-highlighting (eri)21
packages, accessibility, syntax-highlighting
How to Worry About npm Package Weight (chr/css)20
dependencies
Lerna: A Tale of Renaming npm Packages19
dependencies, refactoring, tooling
Validating Dependencies in the Project With npm-check and depcheck18
dependencies, security, maintenance, auditing, tooling
Introducing npx: An npm Package Runner (zka)17
introductions, npx, nodejs
10 Node.js Best Practices: Enlightenment From the Node Gurus16
nodejs, best-practices, environments, event-loop, naming, scalability, caching, express
Solving npm Scripts Problems in JavaScript Projects (hcr)15
yarn, javascript
Why npm Scripts? (css)14
nodejs, conversion, linting, minification, compression, sprites, images, examples
why-is-node-running13
packages, nodejs
How to Solve the Global npm Module Dependency Problem12
how-tos, dependencies
image-dimensions (sin)11
packages, images
Learning Node.js: The “npm link”10
videos, nodejs
9 Quick Tips About npm9
tips-and-tricks, nvm, command-line
Peer Dependencies (dom)8
nodejs, dependencies
Madge7
packages, dependencies, visualization
npm Package Size Checker6
tools, exploration, auditing, debugging, dependencies
npm, Yarn, and pnpm Command Converter5
tools, exploration, conversion, yarn, pnpm, command-line
npm Package Types Checker4
tools, exploration, auditing, debugging, dependencies, typescript, type-safety
npm Dependency Visualizer3
tools, exploration, auditing, debugging, dependencies, visualization
npm Package Download Statistics Checker2
tools, exploration, auditing, debugging, dependencies, metrics
npm Package Checker1
tools, exploration, auditing, debugging, dependencies