DEV Community

npm

Node Package Manager

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
npm Scripts and package.json: The Complete Guide (2026)

npm Scripts and package.json: The Complete Guide (2026)

1
Comments
5 min read
Mini Shai-Hulud: A persistent supply-chain worm

Mini Shai-Hulud: A persistent supply-chain worm

Comments
3 min read
Angular 21 Multiselect Dropdown: A Migration-Friendly Component with Live Functional Tests

Angular 21 Multiselect Dropdown: A Migration-Friendly Component with Live Functional Tests

Comments
9 min read
I Built ShellReq - A Native API Client for VS Code & Terminal

I Built ShellReq - A Native API Client for VS Code & Terminal

Comments
2 min read
GoBadge v2: From Module Stats to Universal Badges

GoBadge v2: From Module Stats to Universal Badges

Comments
2 min read
Architectural Collapse: How Extension Poisoning, Node Vulnerabilities, and Infrastructure Fog Enabled the GitHub Repository Breach

Architectural Collapse: How Extension Poisoning, Node Vulnerabilities, and Infrastructure Fog Enabled the GitHub Repository Breach

Comments
5 min read
The File Problems Every React Native App Eventually Hits

The File Problems Every React Native App Eventually Hits

Comments
5 min read
An npm Downloads Comparison Chart in 300 Lines of Vanilla JS — Nice-Tick Math and API-Direct Fetch

An npm Downloads Comparison Chart in 300 Lines of Vanilla JS — Nice-Tick Math and API-Direct Fetch

Comments
5 min read
Bumblebee vs OSV-Scanner: Two Takes on Supply Chain Scanning

Bumblebee vs OSV-Scanner: Two Takes on Supply Chain Scanning

1
Comments
4 min read
Publishing a reusable React UI package as an npm module

Publishing a reusable React UI package as an npm module

Comments
1 min read
GitHub confirms internal repository breach via poisoned VS Code extension

GitHub confirms internal repository breach via poisoned VS Code extension

1
Comments
2 min read
Why You Shouldn't Run npm install in Production Containers

Why You Shouldn't Run npm install in Production Containers

Comments
2 min read
npm Supply Chain Audit: The Checklist Most Teams Stop Too Early

npm Supply Chain Audit: The Checklist Most Teams Stop Too Early

Comments
6 min read
如何在恶意包进入你的项目前阻断它?用 SupplyChain Sentry 给 npm 依赖上个保险

如何在恶意包进入你的项目前阻断它?用 SupplyChain Sentry 给 npm 依赖上个保险

Comments
1 min read
How We Catch the Axios DPRK RAT — Directly in Your IDE

How We Catch the Axios DPRK RAT — Directly in Your IDE

Comments
3 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.