Package Managers

Feeds to Scour
SubscribedAll
Scoured 817 posts in 9.3 ms

What to Expect from the RPM 6.1 Package Manager

 🧹Linters  Content type: Blog
linuxtoday.com·

docs(release): fix sequential patch numbering · openclaw/openclaw@fb9dc86

 🦀Rust  Content type: Code
github.com·

I made a browser puzzle site for playing more Pips-style logic puzzles after the daily

 🧪Vitest
pips2.com··r/SideProject

someone actually leaked the Miasma supply chain attack toolkit source code on github

 🌱Open Source

Malware Insights: Miasma Campaign

 🟨JavaScript

A package manager for AI assets (and why the lock file is per-user)

 🔧Dev Tooling  Content type: Blog

DWP trials PIP changes affecting thousands of claimants

 Taskwarrior  Content type: News
independent.co.uk·

New IronWorm Malware Hits 36 Packages In npm Supply-Chain Attack

 🌱Open Source
it.slashdot.org·

PIP bill for 16-24s to SOAR to £9BILLION a year in fresh blow to economy as almost a million youths set to claim by 2040

 🌱Open Source  Content type: News
thesun.co.uk·

Lazarus Group Uses npm Brandjacking Campaign to Target Developers

 🟨JavaScript
hackread.com·

Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks

 🌱Open Source
securityweek.com·

Vulnerability and malware checks in uv

 🦀Rust  Content type: Blog

Nuts – pip/NPM for Java with first-class workspaces and JDK provisioning (9y+)

 💻CLI Tools  Content type: Code
github.com··Hacker News

pnpm 11.5 Adds Support for Recognizing npm Staged Publishes

 🔧Dev Tooling  Content type: Blog
socket.dev·

Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System

 🟨JavaScript  Content type: Blog
aikido.dev·

Why Developer Onboarding Should Be Contract-First

 💻CLI Tools  Content type: Blog
ota.run··DEV

How 56 npm packages used binding.gyp to steal CI/CD secrets

 🔧Dev Tooling  Content type: Blog
reversinglabs.com·

Shai-Hulud Hades PyPI Campaign: 19 Packages Trojanized via Wheel Startup Hooks

 🦀Rust  Content type: Blog
socradar.io·

Stop Guessing What ^18.2.0 Actually Installs

 🟨JavaScript
devencyclopedia.com··DEV

Config Files That Run Code: Supply Chain Security Blindspot

 🔧Dev Tooling
safedep.io··Hacker News

Keyboard Shortcuts

Navigation

Next / previous item
j/k
Open post
oorEnter
Preview post
v

Post Actions

Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Save / unsave
s

Recommendations

Add interest / feed
Enter
Not interested
x

Go to

Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/

General

Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help