Skip to main content
Scour
Browse
Getting Started
Login
Sign Up
You are offline. Trying to reconnect...
Close
Copied to clipboard
Close
Unable to share or copy to clipboard
Close
📦 Package Managers
Dependency Resolution, Version Constraints, Lock Files, Security
Filter Results
Timeframe
Fresh
Past Hour
Today
This Week
This Month
Feeds to Scour
Subscribed
All
Scoured
24523
posts in
20.0
ms
Every Package You
Install
Can Read Your
Secrets
💣
ZIP Vulnerabilities
eliranturgeman.com
·
5d
·
Hacker News
,
r/programming
·
…
Show HN: macOS app to
ensure
package
managers
only allow packages 1+ week old
❄️
Nixpkgs
github.com
·
1d
·
Hacker News
·
…
Mitigating
the Axios npm supply chain
compromise
❄️
Nix Adoption
microsoft.com
·
12h
·
…
The Hidden Blast
Radius
of the Axios
Compromise
🧪
CBOR Fuzzing
socket.dev
·
12h
·
Hacker News
·
…
npm
’s
Defaults
Are Bad
❄️
Nix Flakes
nesbitt.io
·
1d
·
Hacker News
·
…
Show HN: Home Maker:
Declare
Your Dev Tools in a
Makefile
⚙️
Build Archaeology
thottingal.in
·
4d
·
Hacker News
·
…
Axios
NPM
Package
Compromised
: Supply Chain Attack Delivers Cross-Platform Rat
💣
ZIP Vulnerabilities
snyk.io
·
1d
·
Hacker News
·
…
Understanding
NPM
Malicious Package Detection: A Benchmark-Driven
Empirical
Analysis
🔗
Topological Sorting
arxiv.org
·
2d
·
…
Appy
v26.03
❄️
Nixpkgs
teejeetech.com
·
6d
·
…
Telnyx
,
LiteLLM
and Axios: the supply chain crisis
🌳
Archive Merkle Trees
martinalderson.com
·
2d
·
Hacker News
·
…
Package
Upgrades
Feel Like Russian
Roulette
❄️
Nix Flakes
ziva.sh
·
1d
·
Hacker News
·
…
Simple Ways to Stay Safe When
Installing
New Software
🔒
Secure Boot
forums.anandtech.com
·
4d
·
…
axios 1.14.1 and 0.30.4 on npm are
compromised
- dependency injection via stolen
maintainer
account
💣
ZIP Vulnerabilities
safedep.io
·
2d
·
Hacker News
,
r/javascript
,
r/programming
·
…
What's coming to our GitHub
Actions
2026 security
roadmap
🔒
WASM Capabilities
github.blog
·
6d
·
Hacker News
·
…
Supply chain blast: Top
npm
package
backdoored
to drop dirty RAT on dev machines
❄️
Nix Flakes
theregister.com
·
1d
·
Hacker News
·
…
What We Learned: Axios
NPM
Supply Chain
Compromise
Emergency Briefing
🎫
Kerberos Attacks
sans.org
·
1d
·
…
Inside the
Axios
supply chain
compromise
🔗
Supply Chain
elastic.co
·
1d
·
…
[BUG] Platform-specific
optional
dependencies not being included in `package-lock.json` when
reinstalling
with `node_modules` present · Issue #4828
🔗
Topological Sorting
github.com
·
1d
·
Hacker News
·
…
Detecting
Protracted
Vulnerabilities in Open Source Projects
⚙️
Build Archaeology
arxiv.org
·
2d
·
…
Supply Chain Attack on Axios Pulls Malicious
Dependency
from
npm
🔗
Supply Chain
socket.dev
·
2d
·
Lobsters
,
Hacker News
,
r/programming
·
…
Loading...
Loading more...
Page 2 »
Keyboard Shortcuts
Navigation
Next / previous item
j
/
k
Open post
o
or
Enter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
g
h
Interests
g
i
Feeds
g
f
Likes
g
l
History
g
y
Changelog
g
c
Settings
g
s
Browse
g
b
Search
/
Pagination
Next page
n
Previous page
p
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc
Press
?
anytime to show this help