Loading…
Tag
3 posts

TanStack packages were compromised in a mass npm supply chain attack. Here's a deep-dive into what happened, how the attack worked, and the concrete steps every JavaScript developer must take to protect their projects right now.

No package manager supports minimum release age natively — but you can enforce it. Here's a complete guide for npm, pnpm, Yarn, Bun, and Deno, plus a universal CI script that works everywhere.

A landmark npm RFC proposes making install scripts opt-in by default. This deep-dive covers how the current system works, why it's dangerous, what the RFC proposes, the tradeoffs involved, and how you can protect yourself right now.