Life is about deciding who you are: Join us and decide to be for environmental protection, free education and generous social security, human rights and international law, and, of course, action against oppression and violence (starting with helping the people of occupied Palestine 🇵🇸)! Hide

Frontend Dogma

“npm” News Archive

Definition, related topics, and tag feed

Definition · Supertopics: nodejs, github, package-managers · Subtopics: npx, packages (non-exhaustive) · “npm” RSS feed (per email)

Entry (Sources) and Additional TopicsDate#
npmx (dan/npm)179
websites, packages
Securing npm Is Table Stakes (nza+/cha)178
podcasts, interviews, security, ai
npm to Implement Staged Publishing After Turbulent Shift Off Classic Tokens (sar/soc)177
dependencies, security, github
How We’re Protecting Our Newsroom From npm Supply Chain Attacks (rya/pnp)176
dependencies, security, case-studies
No More Tokens—Locking Down npm Publish Workflows (zac)175
dependencies, security, github, processes
The Shai-Hulud 2.0 npm Worm: Analysis, and What You Need to Know174
security, dependencies
GitLab Discovers Widespread npm Supply Chain Attack (git)173
dependencies, security, gitlab, github, aws, gcp, azure
Automated npm Secret Rotation in GitHub Actions (mhe)172
security, automation, github-actions
Will npm’s New Security Steps Stop Attacks? (rev)171
security, github, maintenance, foss
The State of Node.js 2025 Explained by Its TSC Member (mco/git)170
videos, nodejs
15 Recent Node.js Features That Replace Popular npm Packages (nod)169
nodejs, dependencies, maintenance
How Deno Protects Against npm Exploits (den)168
deno, security
Strengthening npm Security: Important Changes to Authentication and Token Management (git)167
security
Mastering npx: A Cheatsheet for npm and Node.js Power Users166
npx, cheat-sheets, examples, nodejs
Our Plan for a More Secure npm Supply Chain (xco/git)165
dependencies, security, foss
npm Security Best Practices164
security, provenance, best-practices
This May Be the Worst One (the)163
videos, dependencies, security
Ongoing Supply Chain Attack Targets CrowdStrike npm Packages (pvd+/soc)162
dependencies, security
ctrl/tinycolor and 40+ npm Packages Compromised161
dependencies, security
Which npm Package Has the Largest Version Number?160
dependencies, versioning, semver
How to Keep package.json Under Control (tmc/val)159
how-tos, nodejs, dependencies, maintainability
Oh No, Not Again… a Meditation on npm Supply Chain Attacks (tan)158
dependencies, security, microsoft
Anatomy of a Billion-Download npm Supply-Chain Attack157
security, dependencies
npm Author Qix Compromised via Phishing Email in Major Supply Chain Attack (bur+/soc)156
security, dependencies
npm Trusted Publishing With OIDC Is Generally Available (git)155
dependencies, provenance, github
npm “Accidentally” Removes Stylus Package, Breaks Builds and Pipelines (ax/ble)154
stylus
eslint-config-prettier Compromised: How npm Package With 30 Million Downloads Spread Malware153
prettier, eslint, security, malware
npm Phishing Email Targets Developers With Typosquatted Domain (sar/soc)152
security
Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader (soc)151
security, dependencies
30 Years of JavaScript: 10 Milestones That Changed the Web (ric/the)150
javascript, anniversaries, history, ecmascript, ajax, jquery, web-2.0, nodejs, react, typescript, webassembly
npm Targeted by Malware Campaign Mimicking Familiar Library Names (soc)149
malware, security, dependencies, link-lists
npm Should Remove the Default License From New Packages (ISC) (ext)148
dependencies, licensing, foss
A Decade of Impact: How Our npm Packages Hit 1 Billion Downloads and Shaped JavaScript147
dependencies, history, javascript
Malware Found on npm Infecting Local Package With Reverse Shell (rev)146
dependencies, security
Lazarus Strikes npm Again With New Wave of Malicious Packages (soc)145
dependencies, security
@ 11ty/image-color (zac)144
packages, images, colors
Tutorial: Publishing ESM-Based npm Packages With TypeScript (rau)143
tutorials, dependencies, typescript
Is npm Enough? Why Startups Are Coming After This JavaScript Package Registry (kat/red)142
jsr, bun, pnpm, yarn, javascript
Keep Your Node.js Apps Secure With “npx is-my-node-vulnerable” (tre)141
packages, nodejs, security
My Failed Attempt to Shrink All npm Packages by 5% (eva)140
dependencies, compression
How I Open-Sourced My Secret Access Tokens From GitHub, Slack, and npm—and Who Actually Cares139
security, github, slack
Mastering npm Scripts: Automate Everything in Your Frontend Workflow138
dependencies, environments, ci-cd, automation
HTML Conformance: A Comparison of 6.5 npm Validator Packages (With 1.5 Recommendations) (j9t)137
html, conformance, tooling, comparisons
Publishing a Simple Client-Side JavaScript Package to npm With GitHub Actions (sim)136
dependencies, javascript, github-actions
How to Prerelease an npm Package (spa/clo)135
how-tos, dependencies, versioning, semver
Understanding “npm audit” and Fixing Vulnerabilities134
security, vulnerabilities, nodejs
npm vs. npx133
nodejs, npx, comparisons
Significance of package-lock.json or yarn-lock.json132
yarn, comparisons
More npm Packages on Cloudflare Workers: Combining Polyfills and Native Code to Support Node.js APIs (jas+/clo)131
cloudflare, nodejs, apis, dependencies
caniuse-cli (bra)130
packages, support, browsers, web-platform, caniuse, command-line
CSS Style Observer (bra)129
packages, css
How to Create an npm Package (mat)128
how-tos, dependencies
ObsoHTML, the Obsolete HTML Checker (j9t)127
packages, html, quality
The Great npm Garbage Patch126
dependencies, spam, security
Building an “npm create” Package (ach)125
Publishing a TypeScript Module to npm vs. JSR (den)124
videos, typescript, modules, dependencies, jsr, comparisons
Leaner npm Packument (Metadata) Contents (git)123
Supply Chain Security in npm—We Can Be Optimistic About the Future122
dependencies, security, provenance
Create npm Package With CommonJS and ESM Support in TypeScript121
dependencies, commonjs, esm, typescript
npm and Node.js Should Do More to Make ES Modules Easy to Use120
nodejs, esm
What Happens When a Major npm Library Goes Commercial? (mco)119
dependencies, foss
Researchers Uncover npm Registry Vulnerability to Cache Poisoning and DoS Attacks (sar/soc)118
dependencies, vulnerabilities, caching, security
How a Single Vulnerability Can Bring Down the JavaScript Ecosystem117
javascript, dependencies, caching, vulnerabilities, security
CodeFlattener116
packages, javascript
Using Vite to Rebuild Local Dependencies in an npm Workspace115
dependencies, vite
Building an npm Package Compatible With ESM and CJS in 2024114
dependencies, interoperability, esm, commonjs
npm Basics for New Developers (nim)113
fundamentals
Node.js TSC Confirms: No Intention to Remove npm From Distribution (sar/soc)112
nodejs
The Ultimate Guide to Understanding npx vs. npm111
guides, npx, nodejs
eslint-plugin-depend110
packages, maintenance, simplicity
How npm Install Scripts Can Be Weaponized: A Real-World Example of a Harmful npm Package (eth)109
dependencies, examples, security
Why Does “is-number” Package Have 59M Weekly Downloads?108
dependencies
Node.js Community Debate Intensifies Over Enabling Corepack by Default and Potentially Unbundling npm (sar/soc)107
nodejs, corepack, yarn, pnpm, dependencies
Malicious npm Package Masquerades as Noblox.js, Targeting Roblox Users for Data Theft (sar/soc)106
dependencies, security
GitHub, npm Registry Abused to Host SSH Key-Stealing Malware105
github, security, malware, foss
Modern JavaScript Library Starter104
dependencies, libraries
Deceptive Deprecation: The Truth About npm Deprecated Packages103
deprecation, security, dependencies, research
npm in Review: A 2023 Retrospective on Growth, Security, and Quirky Facts (soc)102
retrospectives
When “Everything” Becomes Too Much: The npm Package Chaos of 2024 (soc)101
foss
A Comprehensive Guide to npm Workspaces and Monorepos100
guides, monorepos, yarn, dependencies
I Replaced npm, Yarn, and nvm With pnpm (paw)99
dependencies, yarn, pnpm, nvm
How to Use npm Packages Outside of Node98
how-tos, dependencies, javascript
Secret Scanning Scans Public npm Packages (git)97
github, dependencies, security
TypeScript Monorepo With npm Workspaces (skw)96
monorepos, typescript, architecture
Honey, I Shrunk the npm Package95
dependencies, compression
SSH Keys Stolen by Stream of Malicious PyPI and npm Packages (ble)94
security, ssh, dependencies
npm Provenance General Availability (git)93
github, provenance, security
How to Migrate From npm to pnpm92
how-tos, migrating, pnpm
dependency-time-machine91
packages, dependencies, maintenance, automation
Sophisticated, Highly-Targeted Attacks Continue to Plague npm90
security
Publishing With npm Provenance From Private Source Repositories Is No Longer Supported (git)89
github, provenance, security, foss
Social Engineering Campaign Targeting Tech Employees Spreading Through npm Malware (soc)88
security, malware
A Comprehensive Beginner’s Guide to npm: Simplifying Package Management87
guides, dependencies
Making the Switch: From Yarn/npm to pnpm86
migrating, yarn, pnpm
Identify Unused npm Packages in Your Project (ami)85
dependencies, maintenance
Comparing npm, Yarn, and pnpm Package Managers: Which One Is Right for Your Distributed Project to Handle High Loads?84
yarn, pnpm, comparisons, performance, best-practices
The Massive Bug at the Heart of the npm Ecosystem83
dependencies, security, bugs
Create React UI Lib: Component Library Speedrun82
typescript, react, components
npm Won’t Publish Packages Containing the Word “keygen”81
discussions, dependencies
Comparing the Best Node.js Version Managers: nvm, Volta, and asdf80
nodejs, nvm
npm vs. Yarn vs. pnpm79
yarn, pnpm, comparisons
Generating Provenance Statements78
provenance, security
Introducing npm Package Provenance (git)77
introductions, github, provenance, security, foss
Dissecting npm Malware: Five Packages and Their Evil Install Scripts76
security, malware
Understanding npm Versioning75
dependencies, versioning, semver
One in Two New npm Packages Is SEO Spam Right Now74
seo
The Landscape of npm Packages for CLI Apps73
nodejs, dependencies, command-line
Automatic npm Publishing With GitHub Actions and npm Granular Tokens72
github-actions, automation
Why We Added package.json Support to Deno (tin/den)71
deno, support, nodejs
Speeding Up the JavaScript Ecosystem—npm Scripts (mar)70
javascript, performance, bundling
Unlocking Security Updates for Transitive Dependencies With npm (git)69
dependencies, security, maintenance
Lockfile Trick: Package an npm Project With Nix in 20 Lines68
tips-and-tricks
New npm Features for Secure Publishing and Safe Consumption (git)67
security, dependencies
Migrating From npm to pnpm66
migrating, pnpm
npm Security: Preventing Supply Chain Attacks65
dependencies, security
How to Build, Test, and Publish a TypeScript npm Package in 202264
how-tos, typescript
Why You Should Prefer Using pnpm Over npm and Yarn?63
pnpm, yarn, comparisons
Use “npm query” and jq to Dig Into Your Dependencies62
videos, dependencies, auditing
Phylum Detects Active Typosquatting Campaign Targeting npm Developers61
dependencies, security
depngn60
packages, nodejs, dependencies
Best Practices for Creating a Modern npm Package59
best-practices
Dependabot Unlocks Transitive Dependencies for npm Projects (git)58
dependencies, security, dependabot
4 Ways to Minimize Your Dependencies in Node.js (app)57
nodejs, dependencies
Installing and Running Node.js Bin Scripts (rau)56
installing, nodejs
Introducing the New npm Dependency Selector Syntax (git)55
introductions
Introducing Even More Security Enhancements to npm (git)54
introductions, security
Top 5 npm Vulnerability Scanners53
security, vulnerabilities, tooling
css-browser-support (5t3)52
packages, css, browsers, support
Image Guard (j9t)51
packages, images, compression, performance, jpeg, png, gif, webp, avif
Alternatives to Installing npm Packages Globally (rau)50
installing, dependencies
How to Migrate From Yarn/npm to pnpm49
how-tos, migrating, yarn, pnpm
You May Not Need a Bundler for Your npm Library48
bundling
npm Security Update: Attack Campaign Using Stolen OAuth Tokens (git)47
security, oauth, version-control, github
What npm Can Learn From Go46
Snyk Finds 200+ Malicious npm Packages, Including Cobalt Strike Dependency Confusion Attacks45
javascript, dependencies, security
4 Reasons to Avoid Using “npm link”44
How to Respond to Growing Supply Chain Security Risks?43
how-tos, security, dependencies, nodejs
Update Node Dependencies Automatically, Selectively, or Incrementally42
nodejs, dependencies, yarn
What’s Really Going On Inside Your node_modules Folder? (soc)41
nodejs, dependencies
How to Publish Deno Modules to npm (kit/den)40
how-tos, deno, modules, dependencies
Understanding Dependencies Inside Your package.json (nod)39
nodejs, dependencies, yarn
How to Fix Your Security Vulnerabilities With npm Override38
how-tos, security, vulnerabilities, dependencies
The Basics of package.json (nod)37
fundamentals, nodejs, dependencies, yarn
pkg.land36
websites, packages, dependencies
Monorepos—How the Pros Scale Huge Software Projects (fir)35
videos, monorepos, yarn, pnpm, lerna, nx, comparisons
GitHub’s Commitment to npm Ecosystem Security (git)34
github, security
Yarn vs. npm: Everything You Need to Know33
yarn, comparisons
timefind32
packages, history
Common npm Mistakes Every Developer Should Avoid31
mistakes
npm Security Best Practices (owa)30
security, best-practices
Simple Monorepos via npm Workspaces and TypeScript Project References (rau)29
monorepos, typescript
NPM Global Audit28
packages, security, quality, auditing
Uninstalling Dev Dependencies With npm27
dependencies
“npm ruin dev” (ada/css)26
html, css, javascript, nodejs
What Is Node and When Should I Use It?25
nodejs, javascript
How to Publish an Updated Version of an npm Package (spa/clo)24
how-tos, dependencies
How to Add CSS Vendor Prefixes Automatically (luk)23
how-tos, css, vendor-extensions, automation, tooling, postcss, webpack, gulp
a11y-syntax-highlighting (eri)22
packages, accessibility, syntax-highlighting
How to Worry About npm Package Weight (chr/css)21
dependencies
Lerna: A Tale of Renaming npm Packages20
dependencies, refactoring, lerna
Validating Dependencies in the Project With npm-check and depcheck19
dependencies, security, maintenance, auditing, tooling
Introducing npx: An npm Package Runner (zka)18
introductions, npx, nodejs
10 Node.js Best Practices: Enlightenment From the Node Gurus17
nodejs, best-practices, environments, event-loop, naming, scalability, caching, express
Solving npm Scripts Problems in JavaScript Projects (hcr)16
yarn, javascript
Why npm Scripts? (css)15
nodejs, conversion, linting, minification, compression, sprites, images, examples
why-is-node-running14
packages, nodejs
How to Solve the Global npm Module Dependency Problem13
how-tos, dependencies
image-dimensions (sin)12
packages, images
Learning Node.js: The “npm link”11
videos, nodejs
9 Quick Tips About npm10
tips-and-tricks, nvm, command-line
Peer Dependencies (dom)9
nodejs, dependencies
Madge8
packages, dependencies, visualization
npm Package Size Checker7
tools, exploration, auditing, debugging, dependencies
npm, Yarn, and pnpm Command Converter6
tools, exploration, conversion, yarn, pnpm, command-line
npm Package Types Checker5
tools, exploration, auditing, debugging, dependencies, typescript, type-safety
npm Dependency Visualizer4
tools, exploration, auditing, debugging, dependencies, visualization
npm Package Download Statistics Checker3
tools, exploration, auditing, debugging, dependencies, metrics
npm Package Checker2
tools, exploration, auditing, debugging, dependencies
Dependencies Badge Generator1
tools, exploration, images, dependencies