Package Managers

Feeds to Scour
SubscribedAll
Scoured 640 posts in 12.0 ms

npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders

 🔗Dependency Resolution  Content type: Blog
socket.dev·

shcherbak-ai/licenseal: Fast cross-ecosystem dependency license compatibility checker + Claude Code review skill

 🔗Dependency Resolution  Content type: Code
github.com··Hacker News

Upcoming breaking changes for npm v12 - GitHub Changelog

 🔗Dependency Resolution  Content type: Blog  Content type: Tutorial

GitHub announces npm security changes to tackle supply-chain attacks

 🔗Dependency Resolution  Content type: News
bleepingcomputer.com·

Package Manager Patents

 📊Dependency Graphs  Content type: Blog
nesbitt.io·

GitHub pulls pin on npm's auto-run scripts

 🔗Dependency Resolution  Content type: News

I Replaced Our Commercial Artifact Registry With a Free One After a 5× Renewal Price Hike.

 🔗Dependency Resolution  Content type: Blog
medium.com
·

Stop Guessing What ^18.2.0 Actually Installs

 🔗Dependency Resolution
devencyclopedia.com··DEV

Massive PyPI Supply Chain Attack Harvests Cloud Credentials via Python Startup Hooks

 📦Container Security
orca.security·

Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks

 🔗Dependency Resolution
securityweek.com·

New Shai-Hulud Miasma Wave Hits Hundreds of npm Packages

 🔗Dependency Resolution
malware.news·

Shai-Hulud Hades PyPI Campaign: 19 Packages Trojanized via Wheel Startup Hooks

 🔗Dependency Resolution  Content type: Blog
socradar.io·

Install-script allowlists

 🔗Dependency Resolution  Content type: Blog
nesbitt.io·

pnpm 11.5 Adds Support for Recognizing npm Staged Publishes

 🔗Dependency Resolution  Content type: Blog
socket.dev·

fix docker store seed target packages (#91547) · openclaw/openclaw@c8a8152

 🔗Dependency Resolution  Content type: Code
github.com·

Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave

 🔗Dependency Resolution  Content type: Blog
socket.dev·

I Researched the Red Hat npm Incident — Here's What Every Developer Should Know

 🔗Dependency Resolution  Content type: Code
github.com··DEV

test: isolate npm update smoke env · openclaw/openclaw@53a3d58

 🔗Dependency Resolution  Content type: Code
github.com·

hamj20k/bulkhead-ai: Stop prompt-injection "soup": one import that keeps your instructions and untrusted RAG/tool/web content in separate, structured fields. npm + pip, zero core deps.

 🔗Dependency Resolution  Content type: Code

Pin official npm plugin install records (#88585) · openclaw/openclaw@7b5f75e

 🔗Dependency Resolution  Content type: Code
github.com·

Keyboard Shortcuts

Navigation

Next / previous item
j/k
Open post
oorEnter
Preview post
v

Post Actions

Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Save / unsave
s

Recommendations

Add interest / feed
Enter
Not interested
x

Go to

Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/

General

Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help