DEV Community

npm

Node Package Manager

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
dep-blame: Understand how your dependencies changed

dep-blame: Understand how your dependencies changed

2
Comments
2 min read
CVE-2026-6951 — Bypassing simple-git's Blocklist via the --config Flag (RCE Analysis)

CVE-2026-6951 — Bypassing simple-git's Blocklist via the --config Flag (RCE Analysis)

Comments
7 min read
prisma generate not working: "No command registered" (Prisma 8)

prisma generate not working: "No command registered" (Prisma 8)

Comments
5 min read
ChainDrop Had Valid Provenance. That Was Not Enough.

ChainDrop Had Valid Provenance. That Was Not Enough.

Comments 1
2 min read
Package of the Week: fast-equals scores 95/100, and the one thing dragging it down isn't what you'd guess

Package of the Week: fast-equals scores 95/100, and the one thing dragging it down isn't what you'd guess

Comments
1 min read
Your NPM_TOKEN stops publishing in January 2027. Here's the one-command migration

Your NPM_TOKEN stops publishing in January 2027. Here's the one-command migration

Comments
3 min read
I built an Instagram Reels feed in React Native. Here's what broke.

I built an Instagram Reels feed in React Native. Here's what broke.

Comments
7 min read
I named three developer tools. All three names were taken on npm.

I named three developer tools. All three names were taken on npm.

Comments
3 min read
here is Idiva!

here is Idiva!

Comments
1 min read
✨ Meet Swingly — a tiny character that lives on your webpage and swings gently.

✨ Meet Swingly — a tiny character that lives on your webpage and swings gently.

Comments
1 min read
AI Recommends Packages Attackers Registered First

AI Recommends Packages Attackers Registered First

1
Comments 1
4 min read
What is FNM ?

What is FNM ?

1
Comments
2 min read
Our beta became the version every new customer installed

Our beta became the version every new customer installed

Comments
2 min read
The npm worm playbook for a small team

The npm worm playbook for a small team

Comments 1
6 min read
TanStack npm supply-chain attack: how a Dependabot bump spread a worm

TanStack npm supply-chain attack: how a Dependabot bump spread a worm

1
Comments
10 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.