Frontend Dogma

“npm” Archive

  1. Using Vite to Rebuild Local Dependencies in an npm Workspace · · ,
  2. Building an npm Package Compatible With ESM and CJS in 2024 · · ,
  3. Node.js TSC Confirms: No Intention to Remove npm from Distribution · ·
  4. How npm Install Scripts Can Be Weaponized: A Real-World Example of a Harmful npm Package · · , ,
  5. Why Does “is-number” Package Have 59M Weekly Downloads? · ·
  6. Node.js Community Debate Intensifies over Enabling Corepack by Default and Potentially Unbundling npm · · , , ,
  7. Malicious npm Package Masquerades as Noblox.js, Targeting Roblox Users for Data Theft · · ,
  8. GitHub, npm Registry Abused to Host SSH Key-Stealing Malware · · , ,
  9. Modern JavaScript Library Starter · · ,
  10. Deceptive Deprecation: The Truth About npm Deprecated Packages · · , ,
  11. npm in Review: A 2023 Retrospective on Growth, Security, and Quirky Facts · ·
  12. When “Everything” Becomes Too Much: The npm Package Chaos of 2024 · ·
  13. I Replaced npm, Yarn, and nvm With pnpm · · , , ,
  14. How to Use npm Packages Outside of Node · · , ,
  15. image-dimensions · · ,
  16. Secret Scanning Scans Public npm Packages · · , ,
  17. TypeScript Monorepo With npm Workspaces · · , ,
  18. SSH Keys Stolen by Stream of Malicious PyPI and npm Packages · · , ,
  19. Honey, I Shrunk the npm Package · · ,
  20. npm Provenance General Availability · · , ,
  21. Sophisticated, Highly-Targeted Attacks Continue to Plague npm · ·
  22. Publishing With npm Provenance from Private Source Repositories Is No Longer Supported · · , , ,
  23. Social Engineering Campaign Targeting Tech Employees Spreading Through npm Malware · ·
  24. A Comprehensive Beginner’s Guide to npm: Simplifying Package Management · · ,
  25. Identify Unused npm Packages in Your Project · · ,
  26. The Massive Bug at the Heart of the npm Ecosystem · · ,
  27. Create React UI Lib: Component Library Speedrun · · , ,
  28. npm Won’t Publish Packages Containing the Word “keygen” · · ,
  29. Comparing the Best Node.js Version Managers: nvm, Volta, and asdf · · ,
  30. npm vs. Yarn vs. pnpm · · , ,
  31. Generating Provenance Statements · · ,
  32. Introducing npm Package Provenance · · , , ,
  33. Dissecting npm Malware: Five Packages and Their Evil Install Scripts · ·
  34. One in Two New npm Packages Is SEO Spam Right Now · ·
  35. The Landscape of npm Packages for CLI Apps · · , ,
  36. Automatic npm Publishing With GitHub Actions and npm Granular Tokens · · ,
  37. Why We Added package.json Support to Deno · · , ,
  38. Speeding Up the JavaScript Ecosystem—npm Scripts · · , ,
  39. Unlocking Security Updates for Transitive Dependencies With npm · · , ,
  40. Lockfile Trick: Package an npm Project With Nix in 20 Lines · ·
  41. New npm Features for Secure Publishing and Safe Consumption · · ,
  42. npm Security: Preventing Supply Chain Attacks · · ,
  43. How to Build, Test, and Publish a TypeScript npm Package in 2022 · · ,
  44. Use “npm query” and jq to Dig into Your Dependencies · · , ,
  45. Phylum Detects Active Typosquatting Campaign Targeting npm Developers · · ,
  46. depngn · · , ,
  47. Best Practices for Creating a Modern npm Package · ·
  48. Dependabot Unlocks Transitive Dependencies for npm Projects · · ,
  49. 4 Ways to Minimize Your Dependencies in Node.js · · ,
  50. Installing and Running Node.js Bin Scripts · ·
  51. Introducing the New npm Dependency Selector Syntax · ·
  52. Introducing Even More Security Enhancements to npm · ·
  53. css-browser-support · · , , ,
  54. Imagemin Guard · · , , , , , , , ,
  55. Alternatives to Installing npm Packages Globally · ·
  56. You May Not Need a Bundler for Your npm Library · ·
  57. npm Security Update: Attack Campaign Using Stolen OAuth Tokens · · , ,
  58. What npm Can Learn from Go ·
  59. Snyk Finds 200+ Malicious npm Packages, Including Cobalt Strike Dependency Confusion Attacks · · , ,
  60. 4 Reasons to Avoid Using “npm link” ·
  61. How to Respond to Growing Supply Chain Security Risks? · · , , ,
  62. Update Node Dependencies Automatically, Selectively, or Incrementally · · , ,
  63. What’s Really Going On Inside Your node_modules Folder? · · ,
  64. Understanding Dependencies Inside Your package.json · · , ,
  65. How to Fix Your Security Vulnerabilities With npm Override · · , ,
  66. The Basics of package.json · · , , ,
  67. pkg.land · · ,
  68. GitHub’s Commitment to npm Ecosystem Security · · ,
  69. Yarn vs. npm: Everything You Need to Know · · ,
  70. Common npm Mistakes Every Developer Should Avoid · ·
  71. npm Security Best Practices · · ,
  72. Simple Monorepos Via npm Workspaces and TypeScript Project References · · ,
  73. timefind · · ,
  74. NPM Global Audit · · , , ,
  75. npm, Yarn, and pnpm Command Converter · , , , , ,