Loading…
Tag
2 posts

TanStack packages were compromised in a mass npm supply chain attack. Here's a deep-dive into what happened, how the attack worked, and the concrete steps every JavaScript developer must take to protect their projects right now.

A landmark npm RFC proposes making install scripts opt-in by default. This deep-dive covers how the current system works, why it's dangerous, what the RFC proposes, the tradeoffs involved, and how you can protect yourself right now.