Tech is political: The people under attack in Palestine 🇵🇸, Iran 🇮🇷, and Lebanon 🇱🇧 are people like us. They’re our brothers and sisters, too. Read up on their history, scrutinize what you’re told, and demand that they be respected and included. Hide

Frontend Dogma

“npm” News Archive

Definition, related topics, and tag feed

Definition · Supertopics: nodejs, github, package-managers · Subtopics: npx, packages (non-exhaustive) · “npm” RSS feed (per email)

Entry (Sources) and Additional TopicsDate#
A Worm Just Ate Its Way Through the npm Registry… (fir)190
videos, dependencies, security, tanstack
What to Know in JavaScript (2026 Edition) (chr/fro)189
javascript, ecmascript, standards, frameworks, runtimes, tooling, testing
Post Mortem: Axios npm Supply Chain Compromise188
axios, security
The Hidden Blast Radius of the Axios Compromise (ahm/soc)187
dependencies, axios, security
Claude Code’s Entire Source Code Got Leaked via a Sourcemap in npm, Let’s Talk About It186
claude, anthropic, ai, source-maps
Minimum Release Age Is an Underrated Supply Chain Defense (dan)185
security, dependencies, bun, pnpm, yarn, deno, renovate, dependabot, axios
Axios Compromised on npm—Malicious Versions Drop Remote Access Trojan184
dependencies, axios, security
A Gentle Intro to npm Workspaces, With Visuals (pre)183
introductions
How to Steal npm Publish Tokens by Opening GitHub Issues (nec)182
github, security, ai
How to Publish to npm From GitHub Actions (bah)181
how-tos, github-actions
npmx (dan/npm)180
websites, npmx, packages
Securing npm Is Table Stakes (nza+/cha)179
podcasts, interviews, security, ai
npm to Implement Staged Publishing After Turbulent Shift Off Classic Tokens (sar/soc)178
dependencies, security, github
How We’re Protecting Our Newsroom From npm Supply Chain Attacks (rya/pnp)177
dependencies, security, case-studies
No More Tokens—Locking Down npm Publish Workflows (zac)176
dependencies, security, github, processes
The Shai-Hulud 2.0 npm Worm: Analysis, and What You Need to Know175
security, dependencies
GitLab Discovers Widespread npm Supply Chain Attack (git)174
dependencies, security, gitlab, github, aws, gcp, azure
Automated npm Secret Rotation in GitHub Actions (mhe)173
security, automation, github-actions
Will npm’s New Security Steps Stop Attacks? (rev)172
security, github, maintenance, foss
The State of Node.js 2025 Explained by Its TSC Member (mco/git)171
videos, nodejs
15 Recent Node.js Features That Replace Popular npm Packages (nod)170
nodejs, dependencies, maintenance
How Deno Protects Against npm Exploits (den)169
deno, security
Strengthening npm Security: Important Changes to Authentication and Token Management168
security
Mastering npx: A Cheatsheet for npm and Node.js Power Users167
npx, cheat-sheets, examples, nodejs
Our Plan for a More Secure npm Supply Chain (xco)166
dependencies, security, foss
npm Security Best Practices165
security, provenance, best-practices
This May Be the Worst One (the)164
videos, dependencies, security
Ongoing Supply Chain Attack Targets CrowdStrike npm Packages (pvd+/soc)163
dependencies, security
ctrl/tinycolor and 40+ npm Packages Compromised162
dependencies, security
Which npm Package Has the Largest Version Number?161
dependencies, versioning, semver
How to Keep package.json Under Control (tmc/val)160
how-tos, nodejs, dependencies, maintainability
Oh No, Not Again… a Meditation on npm Supply Chain Attacks (tan)159
dependencies, security, microsoft
Anatomy of a Billion-Download npm Supply-Chain Attack158
security, dependencies
npm Author Qix Compromised via Phishing Email in Major Supply Chain Attack (bur+/soc)157
security, dependencies
npm Trusted Publishing With OIDC Is Generally Available156
dependencies, provenance, github
npm “Accidentally” Removes Stylus Package, Breaks Builds and Pipelines (ax/ble)155
stylus
eslint-config-prettier Compromised: How npm Package With 30 Million Downloads Spread Malware154
prettier, eslint, security, malware
npm Phishing Email Targets Developers With Typosquatted Domain (sar/soc)153
security
Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader (soc)152
security, dependencies
30 Years of JavaScript: 10 Milestones That Changed the Web (ric)151
javascript, anniversaries, history, ecmascript, ajax, jquery, web-2.0, nodejs, react, typescript, webassembly
npm Targeted by Malware Campaign Mimicking Familiar Library Names (soc)150
malware, security, dependencies, link-lists
npm Should Remove the Default License From New Packages (ISC) (ext)149
dependencies, licensing, foss
A Decade of Impact: How Our npm Packages Hit 1 Billion Downloads and Shaped JavaScript148
dependencies, history, javascript
Malware Found on npm Infecting Local Package With Reverse Shell (rev)147
dependencies, security
Lazarus Strikes npm Again With New Wave of Malicious Packages (soc)146
dependencies, security
@11ty/image-color (zac)145
packages, images, colors
Tutorial: Publishing ESM-Based npm Packages With TypeScript (rau)144
tutorials, dependencies, typescript
Is npm Enough? Why Startups Are Coming After This JavaScript Package Registry (kat/red)143
jsr, bun, pnpm, yarn, javascript
Keep Your Node.js Apps Secure With “npx is-my-node-vulnerable” (tre)142
packages, nodejs, security
My Failed Attempt to Shrink All npm Packages by 5% (eva)141
dependencies, compression
How I Open-Sourced My Secret Access Tokens From GitHub, Slack, and npm—and Who Actually Cares140
security, github, slack
Mastering npm Scripts: Automate Everything in Your Frontend Workflow139
dependencies, environments, ci-cd, automation
HTML Conformance: A Comparison of 6.5 npm Validator Packages (With 1.5 Recommendations) (j9t)138
html, conformance, tooling, comparisons
Publishing a Simple Client-Side JavaScript Package to npm With GitHub Actions (sim)137
dependencies, javascript, github-actions
How to Prerelease an npm Package (spa/clo)136
how-tos, dependencies, versioning, semver
Understanding “npm audit” and Fixing Vulnerabilities135
security, vulnerabilities, nodejs
npm vs. npx134
nodejs, npx, comparisons
Significance of package-lock.json or yarn-lock.json133
yarn, comparisons
More npm Packages on Cloudflare Workers: Combining Polyfills and Native Code to Support Node.js APIs (jas+)132
cloudflare, nodejs, apis, dependencies
caniuse-cli (bra)131
packages, support, browsers, web-platform, caniuse, command-line
CSS Style Observer (bra)130
packages, css
How to Create an npm Package (mat)129
how-tos, dependencies
ObsoHTML, the Obsolete HTML Checker (j9t)128
packages, html, quality
The Great npm Garbage Patch127
dependencies, spam, security
Building an “npm create” Package (ach)126
Publishing a TypeScript Module to npm vs. JSR (den)125
videos, typescript, modules, dependencies, jsr, comparisons
Supply Chain Security in npm—We Can Be Optimistic About the Future124
dependencies, security, provenance
Leaner npm Packument (Metadata) Contents123
Create npm Package With CommonJS and ESM Support in TypeScript122
dependencies, commonjs, esm, typescript
npm and Node.js Should Do More to Make ES Modules Easy to Use121
nodejs, esm
What Happens When a Major npm Library Goes Commercial? (mco)120
dependencies, foss
Researchers Uncover npm Registry Vulnerability to Cache Poisoning and DoS Attacks (sar/soc)119
dependencies, vulnerabilities, caching, security
How a Single Vulnerability Can Bring Down the JavaScript Ecosystem118
javascript, dependencies, caching, vulnerabilities, security
CodeFlattener117
packages, javascript
Using Vite to Rebuild Local Dependencies in an npm Workspace116
dependencies, vite
Building an npm Package Compatible With ESM and CJS in 2024115
dependencies, interoperability, esm, commonjs
npm Basics for New Developers (nim)114
fundamentals
Node.js TSC Confirms: No Intention to Remove npm From Distribution (sar/soc)113
nodejs
The Ultimate Guide to Understanding npx vs. npm112
guides, npx, nodejs
eslint-plugin-depend111
packages, maintenance, simplicity
How npm Install Scripts Can Be Weaponized: A Real-World Example of a Harmful npm Package (eth)110
dependencies, examples, security
Why Does “is-number” Package Have 59M Weekly Downloads?109
dependencies
Node.js Community Debate Intensifies Over Enabling Corepack by Default and Potentially Unbundling npm (sar/soc)108
nodejs, corepack, yarn, pnpm, dependencies
Malicious npm Package Masquerades as Noblox.js, Targeting Roblox Users for Data Theft (sar/soc)107
dependencies, security
GitHub, npm Registry Abused to Host SSH Key-Stealing Malware106
github, security, malware, foss
Modern JavaScript Library Starter105
dependencies, libraries
Deceptive Deprecation: The Truth About npm Deprecated Packages104
deprecation, security, dependencies, research
npm in Review: A 2023 Retrospective on Growth, Security, and Quirky Facts (soc)103
retrospectives
When “Everything” Becomes Too Much: The npm Package Chaos of 2024 (soc)102
foss
A Comprehensive Guide to npm Workspaces and Monorepos101
guides, monorepos, yarn, dependencies
I Replaced npm, Yarn, and nvm With pnpm (paw)100
dependencies, yarn, pnpm, nvm
How to Use npm Packages Outside of Node99
how-tos, dependencies, javascript
Secret Scanning Scans Public npm Packages98
github, dependencies, security
TypeScript Monorepo With npm Workspaces (skw)97
monorepos, typescript, architecture
Honey, I Shrunk the npm Package96
dependencies, compression
SSH Keys Stolen by Stream of Malicious PyPI and npm Packages (ble)95
security, ssh, dependencies
npm Provenance General Availability94
github, provenance, security
How to Migrate From npm to pnpm93
how-tos, migrating, pnpm
dependency-time-machine92
packages, dependencies, maintenance, automation
Sophisticated, Highly-Targeted Attacks Continue to Plague npm91
security
Publishing With npm Provenance From Private Source Repositories Is No Longer Supported90
github, provenance, security, foss
Social Engineering Campaign Targeting Tech Employees Spreading Through npm Malware (soc)89
security, malware
A Comprehensive Beginner’s Guide to npm: Simplifying Package Management88
guides, dependencies
Making the Switch: From Yarn/npm to pnpm87
migrating, yarn, pnpm
Identify Unused npm Packages in Your Project (ami)86
dependencies, maintenance
Comparing npm, Yarn, and pnpm Package Managers: Which One Is Right for Your Distributed Project to Handle High Loads?85
yarn, pnpm, comparisons, performance, best-practices
The Massive Bug at the Heart of the npm Ecosystem84
dependencies, security, bugs
Create React UI Lib: Component Library Speedrun83
typescript, react, components
npm Won’t Publish Packages Containing the Word “keygen”82
discussions, dependencies
Comparing the Best Node.js Version Managers: nvm, Volta, and asdf81
nodejs, nvm
npm vs. Yarn vs. pnpm80
yarn, pnpm, comparisons
Introducing npm Package Provenance79
introductions, github, provenance, security, foss
Generating Provenance Statements78
provenance, security
Dissecting npm Malware: Five Packages and Their Evil Install Scripts77
security, malware
Understanding npm Versioning76
dependencies, versioning, semver
One in Two New npm Packages Is SEO Spam Right Now75
seo
The Landscape of npm Packages for CLI Apps74
nodejs, dependencies, command-line
Automatic npm Publishing With GitHub Actions and npm Granular Tokens73
github-actions, automation
Why We Added package.json Support to Deno (tin/den)72
deno, support, nodejs
Speeding Up the JavaScript Ecosystem—npm Scripts (mar)71
javascript, performance, bundling
Unlocking Security Updates for Transitive Dependencies With npm70
dependencies, security, maintenance
Lockfile Trick: Package an npm Project With Nix in 20 Lines69
tips-and-tricks
New npm Features for Secure Publishing and Safe Consumption68
security, dependencies
Migrating From npm to pnpm67
migrating, pnpm
npm Security: Preventing Supply Chain Attacks66
dependencies, security
How to Build, Test, and Publish a TypeScript npm Package in 202265
how-tos, typescript
Why You Should Prefer Using pnpm Over npm and Yarn?64
pnpm, yarn, comparisons
Use “npm query” and jq to Dig Into Your Dependencies63
videos, dependencies, auditing
Phylum Detects Active Typosquatting Campaign Targeting npm Developers62
dependencies, security
depngn61
packages, nodejs, dependencies
Best Practices for Creating a Modern npm Package60
best-practices
Dependabot Unlocks Transitive Dependencies for npm Projects59
dependencies, security, dependabot
4 Ways to Minimize Your Dependencies in Node.js (app)58
nodejs, dependencies
Installing and Running Node.js Bin Scripts (rau)57
installing, nodejs
Introducing the New npm Dependency Selector Syntax56
introductions
Introducing Even More Security Enhancements to npm55
introductions, security
Top 5 npm Vulnerability Scanners54
security, vulnerabilities, tooling
css-browser-support (5t3)53
packages, css, browsers, support
Image Guard (j9t)52
packages, images, compression, performance, jpeg, png, gif, webp, avif
Alternatives to Installing npm Packages Globally (rau)51
installing, dependencies
How to Migrate From Yarn/npm to pnpm50
how-tos, migrating, yarn, pnpm
You May Not Need a Bundler for Your npm Library49
bundling
What npm Can Learn From Go48
npm Security Update: Attack Campaign Using Stolen OAuth Tokens47
security, oauth, version-control, github
Snyk Finds 200+ Malicious npm Packages, Including Cobalt Strike Dependency Confusion Attacks46
javascript, dependencies, security
4 Reasons to Avoid Using “npm link”45
How to Respond to Growing Supply Chain Security Risks?44
how-tos, security, dependencies, nodejs
Update Node Dependencies Automatically, Selectively, or Incrementally43
nodejs, dependencies, yarn
What’s Really Going On Inside Your node_modules Folder? (soc)42
nodejs, dependencies
How to Publish Deno Modules to npm (kit/den)41
how-tos, deno, modules, dependencies
Understanding Dependencies Inside Your package.json (nod)40
nodejs, dependencies, yarn
How to Fix Your Security Vulnerabilities With npm Override39
how-tos, security, vulnerabilities, dependencies
The Basics of package.json (nod)38
fundamentals, nodejs, dependencies, yarn
pkg.land37
websites, packages, dependencies
Monorepos—How the Pros Scale Huge Software Projects (fir)36
videos, monorepos, yarn, pnpm, lerna, nx, comparisons
GitHub’s Commitment to npm Ecosystem Security35
github, security
Yarn vs. npm: Everything You Need to Know34
yarn, comparisons
timefind33
packages, history
Common npm Mistakes Every Developer Should Avoid32
mistakes
npm Security Best Practices (owa)31
security, best-practices
Simple Monorepos via npm Workspaces and TypeScript Project References (rau)30
monorepos, typescript
NPM Global Audit29
packages, security, quality, auditing
Uninstalling Dev Dependencies With npm28
dependencies
“npm ruin dev” (ada/css)27
html, css, javascript, nodejs
What Is Node and When Should I Use It?26
nodejs, javascript
How to Publish an Updated Version of an npm Package (spa/clo)25
how-tos, dependencies
How to Add CSS Vendor Prefixes Automatically (luk)24
how-tos, css, vendor-extensions, automation, tooling, postcss, webpack, gulp
Using npx and npm Scripts to Reduce the Burden of Developer Tools (bnb)23
npx, tooling, productivity
a11y-syntax-highlighting (eri)22
packages, accessibility, syntax-highlighting
How to Worry About npm Package Weight (chr/css)21
dependencies
Lerna: A Tale of Renaming npm Packages20
dependencies, refactoring, lerna
Validating Dependencies in the Project With npm-check and depcheck19
dependencies, security, maintenance, auditing, tooling
Introducing npx: An npm Package Runner (zka)18
introductions, npx, nodejs
10 Node.js Best Practices: Enlightenment From the Node Gurus17
nodejs, best-practices, environments, event-loop, naming, scalability, caching, express
Solving npm Scripts Problems in JavaScript Projects (hcr)16
yarn, javascript
Why npm Scripts? (css)15
nodejs, conversion, linting, minification, compression, sprites, images, examples
why-is-node-running14
packages, nodejs
How to Solve the Global npm Module Dependency Problem13
how-tos, dependencies
image-dimensions (sin)12
packages, images
Learning Node.js: The “npm link”11
videos, nodejs
9 Quick Tips About npm10
tips-and-tricks, nvm, command-line
Peer Dependencies (dom)9
nodejs, dependencies
Madge8
packages, dependencies, visualization
npm Package Size Checker7
tools, exploration, auditing, debugging, dependencies
npm, Yarn, and pnpm Command Converter6
tools, exploration, conversion, yarn, pnpm, command-line
npm Package Types Checker5
tools, exploration, auditing, debugging, dependencies, typescript, type-safety
npm Dependency Visualizer4
tools, exploration, auditing, debugging, dependencies, visualization
npm Package Download Statistics Checker3
tools, exploration, auditing, debugging, dependencies, metrics
npm Package Checker2
tools, exploration, auditing, debugging, dependencies
Dependencies Badge Generator1
tools, exploration, images, dependencies